Remote hiring has expanded access to specialist talent, particularly in technology, fueling companies’ capabilities like never before. But it has also removed many of the physical checks that once supported secure recruitment decisions. A CV, a polished LinkedIn profile and a video interview can now be assembled or altered with dee AI, with Gartner predicting that, by 2028, one in four job candidates globally could be fake.
This matters because hiring is increasingly tied to security. A new technical employee can quickly receive a company device, identity credentials and access to collaboration tools, code repositories and sensitive data. Hire the wrong person, and it becomes a serious breach waiting to happen.
Thus, catching that person before they are given access is vital. But with AI becoming increasingly uncanny, how can this be done? Magen Gicinto, Chief People Officer at Nisos, encountered a deepfake while interviewing for an AI architect-engineer role. Her experience, and subsequent research, can not only show how to spot them, but also just how prolific they have become.
Diagnosing Deepfakes
The obvious concern with deepfakes is a convincing fake video interview. But that is only one part of the problem. Deepfakes work best when they are combined with other AI-generated material: a CV tailored precisely to the job description, a credible-looking employment history, a professional social media profile and answers produced in real time. The aim is not necessarily to fool one person with one flawless performance. It is to create enough consistency across the hiring process that nobody stops to question the identity underneath it.
That makes the issue difficult to solve through intuition alone. Luckily, in Gicinto’s case, the warning came from a discrepancy between the candidate’s public image and the person who appeared on the call. Speaking of her experience, Gicinto said:
“What was on the screen, what I was interviewing, was very different from the picture from his LinkedIn profile and any other Google search by his name."
Yet the candidate had passed initial screening, demonstrating how easily a false identity can be built to satisfy the normal recruitment checks that precede a first interview.
However, if a bad actor has done more preparation beforehand and inconsistencies cannot be seen in their digital footprint, detection moves to the interview itself. These signs can be subtle, but Gicinto points to a few things, such as candidates looking consistently off-screen, unusually long pauses before answers, reluctance to appear on camera, or different people appearing at different interview stages. Other early flags include an online profile created recently despite a supposedly long career, contradictory photographs across LinkedIn and portfolio sites, or a résumé that appears engineered to reproduce the language of a vacancy.
No individual indicator proves fraud. The risk lies in overlooking a collection of inconsistencies because each can be explained away in isolation.
What Can Businesses Do About It?
Having identified the candidate as a likely North Korean operative, Nisos played along with the interview process to extract information on how the attempted deception would develop. This helped the company build an understanding of how to develop defenses against it.



