Deepfake Job Interview Scams: A Verification Checklist
A convincing face and voice do not establish who is on the call. Verify the person, the organisation and the requested access through independent channels before hiring, onboarding or sharing data.
Treat a visual glitch as a prompt to check, not proof of a deepfake
Remote interviews can fail for ordinary reasons: weak bandwidth, virtual backgrounds, noise suppression, camera exposure and accessibility tools can all make a face or voice look unusual. A frozen mouth, delayed audio or smooth skin is not enough to accuse a candidate or recruiter of using a deepfake.
The FBI has warned that stolen personal information, voice spoofing and deepfakes have been used in applications for remote work, including roles with access to customer data, financial information, corporate systems and proprietary material. The useful response is a repeatable identity and access-control process, not a visual guessing game.
Verify the person outside the interview call
Separate the claimed identity from the contact channel. An application email, recruiting-platform account or CV is not independent identity proof. Employers should use an approved identity-proofing process that checks evidence against authoritative or credible sources and links it to the person presenting it. Candidates should confirm the recruiter and vacancy through the company's official website and independently found contact details.
NIST distinguishes identity resolution, validation of evidence and attributes, and verification that the evidence belongs to the applicant. These are digital-identity guidelines, not an employment-screening certification. A live face alone is insufficient; use proportionate checks, human review and a lawful, accessible alternative.
- Confirm the role and interviewer through a known company channel
- Validate identity evidence rather than accepting an image at face value
- Verify that the person presenting the evidence is its rightful owner
- Document exceptions and offer an accessible review route
Employer checklist before and during the interview
Send the interview invitation from a controlled system and keep the role, participants and approved contact details in the hiring record. At the start, confirm the candidate's name and the purpose of the call without asking them to expose unnecessary identity data on camera. Use structured, job-relevant questions whose follow-ups depend on the answer rather than a theatrical request to turn a head or touch a face.
If identity remains uncertain, pause the process and move to the organisation's approved proofing route. A liveness challenge may contribute a signal, but a rehearsed movement can be relayed and an authentic candidate may fail because of disability, device limits or connectivity. Do not allow an improvised challenge to become the sole gatekeeper for employment.
- Use a company-controlled invitation and record the expected participants
- Ask consistent role-specific questions with natural follow-ups
- Do not collect more identity data than the process needs
- Escalate uncertainty without announcing a technical verdict
- Keep a human review and an alternative verification path
Candidate checklist for a suspicious recruiter
A polished video call does not prove that a vacancy or recruiter is real. Check the job on the organisation's own careers site, inspect the sender's full email domain and contact the company through a number or form you found independently. Be especially cautious if the process moves immediately to private messaging, promises employment without meaningful assessment or creates pressure to act before verification.
A legitimate employer should not require a candidate to pay for equipment, training, background checks or release of wages through gift cards, cryptocurrency or a transfer to a private account. Do not install remote-access software, share one-time codes or send banking credentials because a familiar-looking person requested them on video.
Use media detection as one signal in the investigation
If policy and local law allow analysis, preserve the earliest available recording or file and note how it was obtained. Review video, face and voice results separately. Compression, screen recording, translation, animation and poor-quality audio can reduce reliability. A high score supports further review; a low score does not authenticate the person or the job.
Keep source checks and business-process anomalies visible next to the model result. A real recording can be replayed by an impostor, and a compromised corporate account can host a genuine employee's photograph. The question is not only whether the media is synthetic, but whether the identity, organisation and requested action have been independently confirmed.
Keep hiring separate from access and payment approval
Even after a candidate is selected, do not let the interview itself authorize access to code, customer records, payroll, payment systems or proprietary data. Complete identity checks, references and contractual steps before issuing accounts. Apply least privilege, multi-factor authentication and staged access appropriate to the role.
Verify bank details and equipment-delivery addresses through the approved onboarding workflow. A late request to redirect a laptop, change a payroll account or bypass device management is a new risk event and should receive an independent check, even if the interviews appeared normal.
Record, protect and report the evidence
Record the claimed identity, account, contact details, interview time, requested action and checks completed. Retain only what policy and law permit, restrict access and set a deletion period. Avoid circulating biometric or identity material in informal chats merely to ask colleagues whether it looks fake.
If fraud is suspected, preserve originals, notify the platform and the organisation's security or fraud team, and report financial or cybercrime through the appropriate national channel. Describe observations and verification failures rather than presenting an automated result as a final accusation.
Continue with independent verification.
Check suspicious interview mediaPrimary reading
We use original standards, regulators, public institutions and research papers wherever possible. Sources were last checked on 4 September 2026.