Skip to main content
Hiring Fraud

How to Detect a Deepfake Job Candidate:
8 Checks That Work

Real-time face-swap video now survives a normal interview. It does not survive a profile view, a hand across the face, or an unscheduled call. Eight checks, ordered by hiring stage, following the July and September 2026 allied advisories.

Facial analysis of a video frame showing Action Unit landmarks used to detect synthetic faces

To detect a deepfake job candidate, stop trying to judge video quality and start forcing the deepfake to fail. Real-time face-swap software is now good enough that a static, front-facing video looks convincing. It still breaks when the face turns to profile, when a hand passes in front of it, when the call starts without warning, and when expressions have to keep time with unscripted speech. On 31 July 2026, eleven allied governments warned that North Korean IT operatives are using real-time deepfake video to impersonate real people in live job interviews. On 18 September 2026, Australia, Germany, Japan and the United States published a second advisory: the same regime's fake-recruiter campaign, tracked as WaterPlum, compromised more than 30,000 devices and 7,000 cryptocurrency wallets. The eight checks below are ordered by hiring stage. No single check is decisive; together they make a deepfake candidacy expensive to sustain.

A deepfake job candidate is an applicant whose face, voice or both are synthetically generated or swapped in real time during a remote interview, usually to impersonate a real person whose identity has been stolen or borrowed. The goal is employment and system access, not the salary alone: in the DPRK IT worker scheme, wages fund weapons programmes and access is used for data theft and extortion.

What changed in 2026

Fraudulent remote hiring is not new. What changed this year is the live part. Earlier schemes used stolen photos, AI-written CVs and a camera that was always "broken". The July advisory, signed by the United States, Japan, South Korea and, for the first time, France, Germany, Italy and the Netherlands, describes video feeds that "appear to be manipulated or artificially generated" during conference calls, with operators working from North Korea, China, Russia, Southeast Asia and Africa while appearing to sit in a Western home office. The same advisory's practical guidance is blunt: require live, unscheduled video calls and ask the candidate to perform unexpected physical actions, move within the room or hold up a specific object.

The September advisory covers the mirror image. Operatives pose as recruiters, send developers a "coding assignment", and the file installs remote-access trojans and information stealers that take credentials, keystrokes, identity documents and wallet data. Your organisation can be hit from both directions in the same quarter: a fake candidate joining your team, and a real employee compromised by a fake job offer.

The eight checks, by hiring stage

#CheckStageWhat it defeatsCost to run
1Independent identity verificationPre-screenStolen or borrowed identities, fabricated work historyLow: existing BPSS / right-to-work checks
2Live, unscheduled first callFirst interviewRehearsed face-swap setups, pre-recorded segmentsNone
3Physical-action challengeEvery video interviewFace-swap models trained on frontal faces; breaks on profile views and occlusionNone, two minutes
4Expression timingEvery video interviewLip-sync lag, smoothed micro-movements, expressions that do not track speechTrained interviewer, or behavioural analysis tooling
5Unrelayable questionsTechnical interviewOperators relaying answers; AI-generated responses read aloudNone
6Verified in-person or location stepOfferLaptop farms and reshipping to facilitatorsModerate: travel or a verified courier
7Payroll and device controlsOnboardingPayment to third parties; remote-control tooling on company kitLow: finance and IT policy
890-day behavioural baselinePost-hireInfiltrators who passed every hiring checkLow if UEBA already runs

1. Verify identity outside the interview

Every detail a fake candidate gives you, from the LinkedIn profile to the referee's phone number, may be controlled by the same operator. Verify documents through your screening provider, call previous employers on numbers you find yourself, and treat a candidate whose digital history begins two years ago with care. In the UK, the NPSA employment screening guidance and the Baseline Personnel Security Standard already cover most of this; the failure mode is skipping it for contractors and fast-tracked technical hires.

2. Make the first video call live and unscheduled

A convincing real-time swap needs a prepared source face, a tuned model and a stable setup. Starting the first call at fifteen minutes' notice, with the camera on from the first second, removes the window to prepare. Candidates with a genuine reason to decline can rebook; a pattern of avoiding unscheduled video is itself a signal.

3. Run a physical-action challenge

This is the single most effective zero-cost check, and it is the one the July advisory names. Ask the candidate to turn their head fully to the side and hold it, to pass a hand slowly across their face, to hold up a named object such as a specific coin or the day's newspaper, and to stand and move to another part of the room. Face-swap models are trained overwhelmingly on frontal faces. At profile angles the mask warps or detaches; when a hand crosses the face, fingers merge into skin or the swapped face briefly renders over the hand. Ask naturally, as part of a "quick camera check", and ask everyone, so genuine candidates are not singled out.

4. Watch expression timing, not pixel quality

Pixel-level artefacts are disappearing with every model release. Timing is harder to fake. A genuine smile has a characteristic onset, apex and offset driven by specific muscle groups, and it arrives slightly before or with the words that motivate it. Synthetic faces tend to smooth or drop the small, fast facial movements, hold expressions unnaturally evenly, and lag the audio by a few frames, most visibly on plosive sounds (p, b, m) where the lips must close. This is the layer behavioural analysis tools address; see how temporal coherence exposes deepfakes for the underlying method, based on the Facial Action Coding System.

5. Ask questions that cannot be relayed

Many operations split the work: one person on camera, another answering technical questions off-screen, or an AI generating answers that are read aloud. Unscripted follow-ups ("why that approach and not the obvious one?"), questions about the candidate's claimed home city, and live problem-solving on a shared screen expose the gap between question and answer. Watch for eyes tracking a second screen and a consistent pause before every substantive reply.

6. Require one verified in-person or verified-location step

The cheapest defeat of the whole scheme is physical. Where you can, meet the hire in person before granting system access. Where you cannot, ship equipment only to an address that matches verified identity documents, never to a "temporary" address or a friend's house. US prosecutions have repeatedly centred on laptop farms: facilitators who receive company laptops and host them so remote operators appear to be working domestically.

7. Control payroll and devices

Match the payee name to the verified identity and refuse payment to third parties, payment platforms in other names, or cryptocurrency. On the device side, flag remote-access and remote-control tooling that the role does not need, and geolocation or VPN patterns inconsistent with the hire's stated location. For UK organisations, paying a DPRK worker, even unknowingly, can create sanctions exposure; the Office of Financial Sanctions Implementation published guidance on DPRK IT workers in 2024.

8. Baseline behaviour for the first 90 days

Some infiltrators will pass every hiring check. What catches them is conduct after hiring: bulk repository cloning, access to systems outside the role, working hours that track another time zone, a camera that is never on for team calls, and multiple "employees" whose work output is suspiciously alike. If you already run user and entity behaviour analytics, set a tighter 90-day threshold for new starters. This is the same principle as the five insider threat detection layers: hiring is a point-in-time control, and people who get past it are only caught by continuous signals.

"Require live, unscheduled video calls rather than scheduled interviews, and probe for AI artifacts by asking the candidate to perform unexpected physical actions, move to a different location in the room, or hold up a specific object."

Joint advisory on DPRK IT workers, 31 July 2026, as reported by Tech Times

Does automated deepfake detection work in live interviews?

Partly, and it should be bought with that expectation. Automated detectors trained on yesterday's generators miss today's; accuracy published on benchmark datasets rarely survives a compressed, badly lit video call; and a detector that flags genuine candidates with poor webcams creates its own discrimination risk. The honest position is that automated detection is a triage layer. It tells an interviewer where to look harder and which candidates to put through checks 3 and 6. It should never reject a candidate on its own.

Where detection is most robust is on signals the generator is not optimised for. Pixel realism is what every face-swap model is trained to maximise. The timing relationships between facial muscle movements, and between those movements and speech, are not. That is why behavioural approaches degrade more slowly than artefact-based ones.

Where EchoDepth fits

EchoDepth analyses 44 facial Action Units frame by frame and scores the temporal consistency of expressions: onset and offset timing, co-occurrence of muscle groups that should move together, and alignment with speech. In a hiring context it produces a consistency flag for an analyst, not a verdict, and it runs on-premise so candidate video does not leave your environment. It is most useful for organisations screening high volumes of remote technical hires into sensitive roles, such as defence suppliers, cleared contractors and critical national infrastructure, where checks 1 to 8 are already policy and the gap is interviewer attention at scale. For everyone else, checks 1 to 8 cost almost nothing and should come first.

For UK defence and cleared suppliers

The United Kingdom was not among the named signatories of the July advisory, but UK firms are squarely in scope: remote technical hiring, security-cleared roles and a defence sector growing fast under the Defence Investment Plan. Three practical steps: apply BPSS in full to contractors and agency staff, not only permanent hires; add the physical-action challenge to your standard interview script; and brief engineering staff never to run a recruiter's "take-home test" on a company machine, which is how the WaterPlum campaign got in.

Frequently asked questions

How can you tell if a job candidate is using a deepfake?

Force the deepfake to fail rather than judging video quality. Ask the candidate to turn their head fully to the side, pass a hand across their face, hold up a named object and move within the room: real-time face-swap models break at profile angles and when the face is covered. Start the first call without notice, watch whether lip movements lag speech on sounds like p, b and m, and ask unscripted follow-up questions that an off-screen operator cannot relay quickly.

What did the July 2026 advisory on North Korean IT workers say?

On 31 July 2026, eleven allied governments, including the United States, Japan, South Korea, France, Germany, Italy and the Netherlands, warned that North Korean IT operatives are using real-time AI deepfake video to impersonate real people in live job interviews. It recommended live, unscheduled video calls, physical-action challenges during interviews, in-person verification, independent identity checks and verifying banking details before payment.

What is the WaterPlum or Contagious Interview campaign?

It is a North Korean operation in which operatives pose as recruiters and send software developers fake coding assignments that install remote-access trojans and information stealers. A joint advisory from Australia, Germany, Japan and the United States on 18 September 2026 attributed at least 30,000 compromised devices, more than 7,000 cryptocurrency wallets and about $10.71 million in thefts to the campaign.

Can deepfake detection software reliably catch fake candidates?

Not on its own. Detectors trained on older generators miss newer ones, and compressed video calls degrade accuracy. Automated detection is best used as triage that directs interviewers to run physical-action challenges and in-person verification. Behavioural approaches that analyse the timing of facial muscle movements degrade more slowly than pixel-artefact detectors because generators are not optimised for timing.

Is it legal to test candidates for deepfakes in the UK?

Asking every candidate to perform the same camera check is an ordinary interview practice. Automated analysis of candidate video involves biometric data, which is special category data under UK GDPR, so it needs a lawful basis, a data protection impact assessment, transparency to candidates and human review of any flag. Apply the same checks to all candidates to avoid discrimination risk.

Related capability

Behavioural consistency flags for high-volume remote hiring

44 Action Units scored for timing consistency. On-premise. Analyst-led flags, never automated rejection.