Candidate Fraud Is an Interview Problem, Not a Background-Check Problem

Quick answer
Candidate fraud is deliberate misrepresentation of identity, credentials or performance during hiring. A background check verifies a record after the offer, so it cannot catch a different person on the video call. Greenhouse found 91% of US hiring managers have caught or suspected AI-driven misrepresentation. The interview is where this is observable, so that is where the control belongs.
Somewhere in your last twenty interview loops, an interviewer had a feeling.
The answers arrived a beat late, the way they do when someone is reading. The video was slightly too smooth. The candidate who wrote a sharp take-home could not extend a single line of it out loud. The interviewer mentioned it to the recruiter afterwards, the recruiter agreed it was a bit odd, and then the loop moved on, because there was nowhere to put the observation. No field, no owner, no next step. The candidate advanced.
That is the actual shape of candidate fraud in an enterprise hiring process. It is detected by people in interviews and lost in processes that were never designed to receive it. Meanwhile the control everyone points to, the background check, runs weeks later and verifies something else entirely.
What is candidate fraud?
Featured snippet
Candidate fraud is deliberate misrepresentation during hiring: fabricated credentials, undisclosed assistance during interviews, or another person presenting as the candidate. It runs on a spectrum from embellishment to identity substitution. Gartner predicts that by 2028, one in four candidate profiles worldwide will be fake and contain material identity misrepresentation.
The term covers three different problems, and conflating them is why most responses to it miss.
* Embellishment. A stretched title, a date that has been rounded, a project someone contributed to rather than led. Old, common, and mostly a reference-check problem.
* Assisted performance. The candidate is real, the performance is not theirs. Greenhouse's 2025 AI in Hiring Report has 40% of US candidates reporting the use of prompt injection to get past automated filters, and hiring managers describing candidates reading from AI-generated scripts during live interviews.
* Identity substitution. The person on the call is not the person who will do the job, or is not who they claim to be at all. 36% of US job seekers told Greenhouse they have used AI to alter their appearance, voice or background during a video interview. In a 2Q25 Gartner survey of 3,000 candidates, 6% admitted to interview fraud, either posing as someone else or having someone else pose as them. That figure is self-reported, which makes it a floor rather than an estimate.
The first is an old nuisance. The third is a security incident that arrives through your recruiting funnel. And the interview is the only stage that touches all three, which is why 50% of US hiring managers now name authenticity as their single biggest hiring challenge.
Why doesn't the background check catch it?
Featured snippet
Because it verifies a record, not the person who sat the interviews, and it runs after the offer. HireRight found only three in five employers run any identity check at all, while more than three quarters uncovered candidate discrepancies in the past year. A real record can belong to someone who was never on the call.
Two structural limits, neither of which is a criticism of screening vendors.
The first is timing. A background check runs at the end, usually after a verbal offer. By then the loop has already been assembled, the panel hours have already been spent, and the team is emotionally committed to a hire. Every dollar the process was supposed to protect is already gone. It is the same asymmetry as post-interview ghosting, where the expensive part happens before the signal arrives.
The second is scope. A background check confirms that a record exists and that it matches the name and identifiers provided. It is very good at that. It has no view of who was on the Zoom call. The North Korean IT worker cases the US Department of Justice charged in June 2025 are the clean illustration: the schemes obtained employment at more than 100 US companies, including many Fortune 500 companies, by using the compromised identities of more than 80 real US persons. Those checks did not fail. They passed, correctly, on identities that were genuine and stolen.
CrowdStrike tracked one of the groups behind this to more than 320 companies in twelve months, a 220% year-over-year increase, and describes real-time deepfake tooling used specifically to mask identity during video interviews. The attack surface is the interview, not the screening report.
HireRight's 2025 benchmark of more than 1,000 HR, risk and talent professionals shows the gap. More than three quarters found candidate discrepancies in the past twelve months, but only three in five run identity checks, one in six say their business has already experienced identity fraud during hiring, and another three in ten do not know whether it has.
Where does fraud actually surface in a loop?
Featured snippet
In the second half of the loop, not the first. Screening calls are short, scripted and easy to perform. Panels and technical rounds are longer, less predictable, and have several observers. Duration, unpredictability and repeat exposure are what expose a substituted or coached candidate, and all three are scheduling decisions.
Take the three stages in order and ask what each one can see.
* The recruiter screen. Fifteen to thirty minutes, one observer, a predictable script covering availability, interest and compensation. This is the easiest stage in the process to perform, and structurally the weakest place to look for fraud. As the screening stage gets more automated, it also gets more predictable, which cuts both ways.
* The panel or technical round. Longer, harder to script, and it contains the thing no preparation survives: a follow-up question that departs from the expected path. It also has multiple observers who can compare notes. This is where the feeling in the opening paragraph almost always occurs.
* The final or onsite round. The strongest signal and the rarest. Gartner reports that organizations combating candidate fraud are turning to video interviews (81%) and in-person interviews (74%), and that 62% of candidates say they are more likely to apply when the interview is conducted in person. The control most people reach for is a scheduling and logistics problem before it is anything else.
Interview continuity, panel composition and where the in-person round sits are all coordination decisions. That layer is what candidate.fyi handles across the loop.
153 Interviews Per Coordinator, Per Week.
The average team manages 38 manually. candidate.fyi's AI coordination layer gives your team 4x the capacity — without adding headcount.
What can an interviewer realistically verify?
Featured snippet
Consistency, not identity. An interviewer cannot authenticate a document or a face. They can notice whether the person in round three is the person from round one, whether spoken answers match written work, and whether responses arrive at human speed. Those are observations to route, not verdicts to reach.
This is the line that keeps the whole thing defensible, so it is worth stating precisely.
Interviewers cannot verify identity. They are not trained to authenticate documents, asking a candidate for ID mid-process raises questions that belong to legal and talent operations rather than to a hiring manager on a Tuesday, and a face is not evidence. Any process that quietly asks interviewers to make identity determinations is both unreliable and a liability.
What interviewers can do is notice inconsistency, which is a different and much more useful thing.
* Whether the person in this round is recognizably the person from the last one.
* Whether the candidate can extend their own written work in conversation, past the depth the document reached.
* Whether answers track the question or track a script, particularly when a follow-up goes somewhere the script did not anticipate.
* Whether the lag between question and answer is conversational.
None of that is proof, and treating it as proof is its own failure. Candidate trust is already thin: 46% of US job seekers say their trust in hiring has fallen over the past year, 42% blame AI directly, and among Gen Z entry-level workers that figure reaches 62%. A process that treats every candidate as a suspect will lose real candidates faster than it catches fake ones. The goal is a route for a doubt, not a verdict from an interviewer.
What to change at the coordination layer
Featured snippet
Design the loop so identity is observable and observations have somewhere to go: one interviewer continuous across rounds, the least scripted round before the offer, an accurate record of who actually attended, and a named owner for doubts. A 14% structural reschedule rate quietly undoes all four.
Four changes, none of which requires a new vendor.
* Keep one interviewer continuous across rounds. Substitution is only detectable by someone with a prior. Most panels are built for availability, seniority and load balancing, and nobody checks whether a single human sees the candidate twice. Across recruiting organizations the structural reschedule rate sits at 14%, roughly one interview in seven rebuilt at least once, and every rebuild swaps interviewers on availability alone. Continuity is the first thing a reschedule costs you and nobody has ever logged it as a cost.
* Put the least scripted round before the offer. If the deepest, longest, most improvisational conversation happens in week one and the last three weeks are process, the loop stops learning exactly when the stakes rise.
* Record who actually attended. Not who was invited. The rounds where a stand-in joined at short notice are precisely the rounds with no reliable observer, and in most teams that fact exists only in a coordinator's memory.
* Give a doubt one place to go. A named owner, a field on the interview, a defined next step. This is the change that would have caught the loop in the opening paragraph, and it costs nothing except deciding who owns it. In practice that ownership belongs to recruiting operations, and where no such function exists it belongs to whoever gets asked afterwards how this happened.
All four are decisions about who is in which interview, in what order, with what record kept. That is coordination, and it is the layer where most loops already break for reasons that have nothing to do with fraud.
Isn't this what background checks and verification vendors are for?
Featured snippet
Partly, and both are worth having. Neither is an interview control. A check confirms a record exists and matches the name given, once, after the loop. Identity verification at application helps most in high-volume remote hiring. Neither one observes the person answering questions in round three.
The strongest version of the objection is that this is a solved problem with a procurement answer: buy document and liveness verification, run it at application, and stop asking interviewers to notice things. For high-volume remote roles that is a reasonable investment, and the tooling is better than it was two years ago.
It still does not remove the interview problem. Verification at application authenticates whoever completes the verification step, which is not necessarily whoever appears at round three, and a check at the end confirms a record after every hour of panel time has been spent. If a loop has no continuity and no attendance record, adding a vendor at either end leaves the middle exactly as blind as it was. 74% of hiring managers told Greenhouse they are more worried about fake credentials, deepfakes or misrepresented experience than a year ago. What has not moved at the same rate is process design.
The bottom line
Featured snippet
Candidate fraud is caught by people in interviews and lost in processes with nowhere to record it. Background checks verify records after the cost is spent. Fix the loop first: continuity across rounds, an unscripted round before the offer, a real attendance record, and a named owner for doubts.
Remote-first hiring quietly removed the only step where a human looked at a candidate in person, and nobody decided to remove it. It went with the office. What replaced it was a video call that is now cheap to fake, followed by a check that verifies a document.
The fix is not another layer of suspicion pointed at candidates. It is a loop built so that the people already in the room can see what they are looking at, and so that what they notice reaches someone who can act on it.
Frequently asked questions
What is candidate fraud in recruitment?
Candidate fraud is deliberate misrepresentation by an applicant during hiring. It ranges from inflated titles and dates through undisclosed AI assistance during live interviews to full identity substitution, where the person interviewing is not the person who would do the job. The first is a reference problem. The last is a security incident that arrives through the recruiting funnel.
How do you detect a deepfake candidate in an interview?
By designing the loop rather than by scrutinizing the video. Keep at least one interviewer across multiple rounds so substitution has a witness with a prior, include a long unscripted conversation that requires the candidate to extend their own written work, and record who actually attended each round. Interviewers should report inconsistency to a named owner rather than attempt an identity determination themselves.
Do background checks catch identity fraud?
Not reliably. A background check verifies that a record exists and matches the identifiers given, which is a different question from whether the person who sat the interviews is that individual. It also runs after the offer, once the interview cost has been spent. HireRight found that only three in five employers run any identity check at all.
What is interview fraud detection?
Interview fraud detection is the practice of identifying misrepresentation during the interview stage rather than after it, using process design: interviewer continuity across rounds, unscripted follow-up questions, comparison of spoken answers against written work, accurate attendance records, and a defined escalation path when something looks wrong.
Can you ask a candidate for identification during the interview process?
Sometimes, but it is a legal and policy decision rather than a scheduling one, and the rules vary by jurisdiction and by stage. Requests of this kind should be defined in advance with legal and talent operations, applied uniformly to every candidate for a role, and never improvised by an individual interviewer partway through a loop.
How common is candidate fraud?
Common enough to be a design assumption. Greenhouse found that 91% of US hiring managers have caught or suspected AI-driven candidate misrepresentation, and 6% of candidates in a Gartner survey of 3,000 admitted to interview fraud outright. Gartner predicts that by 2028 one in four candidate profiles worldwide will be fake and contain material identity misrepresentation.
If the coordination layer under your interview loop is where these controls would have to live, book a demo and we will walk through what your current loop can and cannot see.
More Articles

5 Tasks Recruiting Coordinators Can Focus on When Scheduling Is Automated
Discover five high-impact tasks recruiting coordinators can prioritize when automated interview scheduling removes admin work. Learn how AI recruiting tools free coordinators to focus on candidate relationships, data analysis, interviewer coaching, process design, and employer brand strategies that improve hiring outcomes.

AI Agent vs. Chatbot: What the Difference Means for Your Recruiting Team
Most recruiting teams are using chatbots, not AI agents and vendors are blurring the line. Here's how to tell the difference and what it changes in your hiring workflow.

8 Best Automated Interview Scheduling Tools with Workday Integration
Comparing the 8 best automated interview scheduling tools that integrate with Workday — evaluated on panel complexity, multi-timezone support, candidate updates, and enterprise controls.
