To identify fake candidates in remote hiring, check identity at three points instead of one: before the final interview, before you ship a laptop or grant access, and again in the first weeks of work. That's the short answer, and it comes from the FBI, which tells employers to verify remote workers "during hiring, onboarding, and throughout the employment." A single ID check at offer time is exactly the gap fraud schemes use.
This used to sound paranoid. It doesn't anymore.
Key Takeaways
- The FBI has warned since 2022 about deepfakes and stolen identities used to apply for remote software jobs.
- In June 2025, the DOJ said North Korean IT workers had gotten jobs at more than 100 US companies using stolen and fake identities.
- Candidate fraud detection is procedural: unscripted video checks, consistent identity data, and attention to address changes before the laptop ships.
- If you use a staffing provider, ask exactly how it verifies identity. The FBI specifically tells employers to check this.
How to Identify Fake Candidates: The Warning Signs
In June 2022, the FBI's Internet Crime Complaint Center reported an increase in complaints about deepfakes and stolen personal information used to apply for remote jobs, including "information technology and computer programming, database, and software related job functions." The tell it described: lip movement that doesn't match the audio, and coughs or sneezes that don't line up with the video. In some cases, background checks found the personal details "belonged to another individual."
A May 2024 FBI alert described North Korean IT workers using US-based helpers to get remote jobs. Its warning signs include candidates who can't answer questions about where they're located, and background noise that sounds like the applicant "is surrounded by others doing similar work." In January 2025, the FBI warned that some of these workers had moved to data extortion, and listed indicators including "face-swapping technology during video job interviews," reused contact details, and multiple logins to one account from different IP addresses in a short period.
In June 2025, the Justice Department announced coordinated actions: the schemes had placed workers at more than 100 US companies, compromised the identities of more than 80 US persons, and relied on laptop farms; agents searched 29 known or suspected ones across 16 states. Victim companies lost at least $3 million.
Gartner adds a forward-looking number. Based on a 2025 survey of 3,000 job candidates, it predicts that by 2028, one in four candidate profiles worldwide will be fake, as reported by HR Dive. That's a prediction, not today's rate. In the same survey, 6% of candidates admitted to interview fraud.
Candidate Fraud Detection, Stage by Stage
Most remote candidates are exactly who they say they are. Identity is simply something you now check on purpose. Here is the process I'd use, built from the FBI's own employer recommendations.
| Stage | What to check | Why |
|---|---|---|
| First video call | Camera on, and ask for something unscripted: turn the head, hold a hand near the face | The FBI has seen face-swapping used in video interviews; unscripted movement is a cheap stress test, not proof either way |
| Screening | Compare name, phone, email and work history across the CV, LinkedIn, and application | The FBI flags reused contact details and duplicate CV content |
| Technical interview | Ask where they are, what time it is there, and follow up | The FBI flags candidates who can't answer questions about their own location |
| Before any laptop ships | Confirm the delivery address matches what you verified; question a late change | The FBI calls out address changes after hire, before laptops arrive |
| First weeks | Least-privilege access; watch for logins from unexpected places or several IPs | The FBI lists multiple logins to one account from various IP addresses as an indicator |
Two more habits help. Keep the same person on camera through the process: a sudden change in voice, accent, or skill between rounds is worth pausing on. And listen to the room, since a laptop farm sounds like a room full of people doing the same job.
Fake Candidates and Staffing Providers
The FBI's 2024 alert tells employers to make sure third-party staffing firms run strong hiring practices and audit them routinely. Ask any provider three questions: how do you verify identity, at what stage, and what happens if the person who starts isn't the person we interviewed?
At Ruzora, every engineer goes through an AI interview and a graded coding assessment before reaching a shortlist. You see blind profiles first; after a founder call and a signed agreement you get identities and interview the engineers you like live. No process stops every scheme, and I won't claim ours does. What it gives you is two separate evaluations before you meet anyone, plus your own live interview, and you should still run your own checks. How to verify a senior engineer covers the skills side, and how to spot a fake senior developer covers people who are real but oversell.
A Concrete Version
A 30-person SaaS company hires a remote backend engineer. On the first call, the candidate's camera is on but the lips run slightly behind the audio. The recruiter asks them to turn to the side and hold a coffee mug up by their cheek. The image glitches. The company ends the process.
A second candidate clears the first three stages. The day before the laptop ships, the candidate asks to change the delivery address to a different state. The CTO asks why and gets a reasonable answer: they're staying with family for a month. The CTO asks for a quick video call from that address, which takes ten minutes, and ships the laptop. In week two, the access logs show logins from one place, the city the engineer named. Total added effort across the hire: under an hour.
The Honest Counterpoint
Over-checking has a cost. Honest candidates have bad webcams, patchy internet, and addresses that change for normal reasons. Treat each signal as a reason to ask a question, not a verdict, or you'll lose the senior engineers you most want.
Be careful about who you suspect, too. The documented schemes involve North Korean operators using stolen US identities and US-based laptop farms, and nothing in the FBI or DOJ material cited here points at candidates from Latin America. Checking every remote hire the same way, US-based ones included, is fairer and works better than profiling.
Frequently Asked Questions
How do you identify fake candidates in recruitment?
Check identity at several stages: unscripted movement on the first video call, consistent details across CV, LinkedIn and application, location questions in interviews, the delivery address before a laptop ships, and access patterns in the first weeks.
How can I tell if a video interview is a deepfake?
Look for lip movement out of sync with the audio, and ask for unscripted movement, like turning the head or putting a hand near the face. The FBI's 2022 alert describes the sync problems specifically.
Should I ask remote candidates for ID?
Verifying identity is reasonable, but how you collect and store ID documents has legal implications that vary by location. This is general information, not legal advice; talk to employment counsel or rely on your provider's documented process. How to evaluate a staff augmentation provider lists what else to ask.
The Bottom Line
Fake candidates in remote hiring are documented by the FBI and DOJ, and the fix is a boring, consistent process that takes under an hour per hire. If you'd rather start from engineers who have already been through an AI interview and a graded coding assessment, Ruzora sends a vetted shortlist within 72 hours. See available engineers, and read what access a developer should have before day one.
Roberto Espinoza is CEO of Ruzora, which helps US startups hire pre-vetted senior LATAM engineers, with a vetted shortlist in 72 hours. See available engineers.
