How do you detect candidate fraud in hiring?
Add verification checkpoints at every hiring stage rather than one check at offer. Screen for five patterns: interview proxies, fabricated credentials, deepfake interviews, employment infiltration and duplicate identities. In interviews, watch for eyes tracking off-screen text and audio out of sync with lip movement — treat any two flags together as grounds for another verification step.
This playbook is for recruiters, hiring managers, and security teams running remote or hybrid hiring. It gives you the verification checkpoints to add at each hiring stage, the red flags to watch in interviews, and the exact steps to verify a candidate's identity, so the person you hire is the person you interviewed.
Know the five frauds you're screening for
| Fraud pattern | How it works | Where it shows up |
|---|---|---|
| Interview proxy | A skilled stand-in passes the interviews; someone else starts the job | Remote technical roles; sharp skill drop after day one |
| Fabricated credentials | Fake degrees, invented employers, references routed to friends | CV claims that only exist as PDFs the candidate provided |
| Deepfake interviews | Real-time face swap or voice conversion on the video call | Lip-sync lag, refusal to move or adjust camera |
| Employment infiltration | Stolen or synthetic identity used to gain inside access or route salary to sanctioned actors | Remote IT roles; mismatched location/device signals |
| Duplicate identities | One person holding multiple jobs or applying repeatedly under variations | Same device or documents behind "different" applicants |
Add verification checkpoints to every hiring stage
Fraud succeeds when identity is checked once, late, and casually. Distribute these checkpoints across your pipeline:
Stage 1: Application
- Collect a government ID capture + live selfie with liveness detection for shortlisted candidates (this alone removes most proxy setups: the interviewee must now match a verified identity)
- Screen for duplicates: same face, document, device, or phone number across multiple applications
- Log device and network data: data-center IPs, anonymizing VPNs, and remote-access tools during assessments are flags to investigate
Stage 2: Interviews
- Camera on, every round. No exceptions for "broken webcams" on final rounds
- Compare the on-screen face against the verified selfie from stage 1
- Ask for one physical interaction per round: turn your head, hold your ID beside your face, pick up the camera. Live deepfake rigs degrade under motion and occlusion
- Keep interviewer notes on fluency and depth per round; sharp inconsistency between rounds is a proxy signal
Stage 3: Offer
- Re-run the biometric check before the contract goes out: same face as stage 1, live selfie, liveness on
- Verify right-to-work through the official channel for your jurisdiction, not by eyeballing documents
- Verify credentials and employment history at the source (steps below)
Stage 4: Day one
- Final selfie match before granting system access. Bind the verified identity to the account, not just the hire
- Confirm working location matches the contract (IP geolocation on first logins)
Stage 5: Ongoing, for sensitive roles
- Periodic re-verification for roles with production, financial, or customer-data access
- Alert on anomalies: impossible travel, new remote-access tooling, credential sharing patterns
Spot these red flags in interviews
| Red flag | What to do |
|---|---|
| Eyes tracking off-screen text; long latency before fluent answers | Ask an unusual follow-up that breaks scripted flow |
| Audio subtly out of sync with lip movement | Request a camera adjustment or head turn |
| Refuses to modify lighting, angle, or background | Reschedule with camera requirements stated in writing |
| Skill level swings between rounds | Repeat one earlier question verbatim in the next round |
| New hire's output doesn't match interview performance | Re-verify identity now, and feed the case back into your screening |
Treat any two flags together as grounds for an additional verification step, not an accusation. False positives happen, and a legitimate candidate passes a re-check in two minutes.
Verify a candidate's professional identity: 5 steps
- Verify the legal identity first. Government ID + biometric selfie match with liveness. Every other check inherits from this step: a verified employment history means nothing if the applicant isn't that person.
- Call employers via numbers you found yourself. Look up the company's HR line independently. Never use reference contact details the candidate supplied.
- Verify credentials with the issuing institution or its official verification service. A PDF certificate is a claim, not evidence.
- Check the footprint for coherence. Profile age, history consistency across sources, and whether the "current employer" actually exists, with real offices, real customers, real staff.
- Confirm right to work through official channels, not document inspection.
Choose a candidate verification platform: evaluation checklist
Manual checks stop scaling past a handful of hires. When you evaluate platforms, score them on:
- Document verification coverage. Candidates hold IDs from everywhere; coverage gaps become fraud gaps
- Biometric match with liveness detection. The anti-proxy, anti-deepfake control; a face match without liveness is decorative
- Duplicate detection. Identity graph across faces, documents, and devices
- Re-verification support. One-click re-checks at offer, day one, and beyond
- Workflow flexibility. Verification slots into your stages, not the vendor's
- Privacy posture. Applicants aren't employees yet; biometric data handling carries GDPR and BIPA exposure. Prefer platforms whose AI models run in-house rather than shipping PII to third-party processors
- Audit trail. When fraud surfaces, you need a defensible record of what was checked and when
The same verification flow that powers customer KYC (document capture, liveness selfie, biometric match, duplicate detection) handles candidate verification; only the trigger point changes. Higher education faces the identical pattern with ghost student fraud.
The rule that makes it all work
One verified identity, confirmed at every stage, from application to system access. Verify the document, verify the human, bind them together, and keep checking.