Benchmark Benefits Consulting

Social Engineering & Fraud

The Person on the Interview May Not Be the Person You Hire: AI, Deepfakes and the New HR Identity Problem

Remote hiring now carries an identity question alongside the qualification question. This guide shows where impersonation can enter the employment lifecycle—and how HR, security and privacy teams can verify people without treating every remote candidate as suspicious.

Published by Benchmark Benefits Consulting · Reviewed September 30, 2026

The person on screen is no longer proof of identity

An HR professional interviews a candidate by video. The answers fit the résumé. The face appears plausible. The candidate advances, receives a laptop and is issued credentials. But the person on screen, the identity documents, the person doing the work and the bank account receiving pay may not all belong to the same human being.

This is not a prediction about what deepfakes might eventually do. In January 2025, the FBI said it had observed North Korean IT workers using artificial intelligence and face-swapping technology during video interviews to conceal their identities. A 2022 FBI warning had already described complaints involving voice spoofing or potential voice deepfakes, stolen personal information and remote applicants for roles with access to customer information, financial data, databases and proprietary material.

In a June 2025 case, the U.S. Department of Justice alleged that a wider remote-worker scheme compromised the identities of more than 80 U.S. people, obtained jobs at more than 100 companies, accessed internal systems and sensitive employer data, and used U.S.-based laptop farms. Those figures are allegations in charging documents, not findings that every defendant was guilty. They nevertheless show why a hiring process can become an access-control failure when identity, device location and account ownership are treated as administrative details.

Evidence boundary: documented schemes do not make ordinary remote applicants presumptively fraudulent. Most candidates and remote workers are legitimate. The control objective is consistent identity assurance for higher-risk access—not profiling by nationality, accent, location, disability, appearance or working arrangement.

Four identities may need to be bound together

A sound process connects: the person interviewed; the identity evidence lawfully reviewed; the person named in the employment or contractor record; and the person who later uses the device, account and payroll destination. A strong interview can test capability and communication. It cannot, by itself, establish that all four are the same.

Follow the risk through the employment lifecycle

The hiring process is part of the organization’s identity and cybersecurity perimeter because it can culminate in credentials, data access, payment authority and trusted relationships. Each stage answers a different question.

Application and automated screening

  • Risk: stolen personal information, synthetic profiles, fabricated histories, reused contact details, automated mass applications or a person applying on someone else’s behalf.
  • Control: do not treat résumé consistency as identity proof. Look for duplicate contact details or substantially identical résumés where lawful, but require human review before drawing conclusions.

Recruiter screening

  • Risk: a proxy candidate, coached answers, false location or communication accounts reused across identities.
  • Control: ask role-specific and history-specific questions; document inconsistencies; give candidates a fair opportunity to explain ordinary discrepancies.

Video interview

  • Risk: face swapping, synthetic or relayed audio, off-camera assistance, a proxy interviewee, or a genuine applicant whose visual appearance is affected by normal compression, accessibility tools or poor connectivity.
  • Control: use video as one signal, not proof. Do not rely on “spot the deepfake” intuition or gimmicks as the only safeguard.

Identity, background and credential checks

  • Risk: stolen or altered documents, fabricated references, false institutions, or a check performed against information supplied by the fraudster.
  • Control: verify through authorized, original and independently sourced channels; ensure consent, adverse-action and employment rules are addressed where applicable.

Offer and onboarding

  • Risk: last-minute changes to address, device destination, telephone number, payment method or identity details; a different person appearing after hire.
  • Control: reconcile material changes before credentials or equipment are released, and document who approved the resolution.

System access

  • Risk: excessive default permissions, shared credentials, unauthorized remote-control software, data exfiltration or rapid access to source code, employee files or financial systems.
  • Control: complete required checks first, issue named accounts, apply least privilege and monitor high-risk access in accordance with policy and law.

Payroll, benefits and employee-data access

  • Risk: redirected pay, mismatched banking details, impersonated change requests, access to tax or benefits information, or exploitation of HR’s trust in an established employee identity.
  • Control: independently verify sensitive changes and alert the person through a previously trusted route.

A deepfake check is not an identity program

Visual artefacts, delayed lip movement, lighting anomalies or unnatural audio can justify a pause, but they are not reliable proof of deception. Ordinary video calls fail. Assistive technology, language interpretation, camera processing, virtual backgrounds and network latency can all create unusual effects. A process that equates “looks strange” with fraud can exclude legitimate candidates and create discrimination, accessibility and privacy problems.

The FBI’s July 2025 remote-worker guidance includes tactics for higher-risk situations, including independently checking identity documents, verifying prior education and employment, scrutinizing device-shipping changes and withholding system access until background checks are complete. Some FBI suggestions—such as in-person steps or unusual video prompts—were issued for a specific national-security threat. They should not be copied into every employer’s universal hiring policy without legal, privacy, accessibility and operational review.

Use independent evidence, not a single performance test

Identity confidence should come from several appropriately chosen signals: verified contact information, authoritative document or credential checks, live interaction, original-source employment or education confirmation, controlled device delivery, account binding and consistency after onboarding. If one signal fails, escalate rather than asking a recruiter to become a forensic examiner.

Benchmark framework

The Human Identity Checkpoint

The Human Identity Checkpoint is a Benchmark-created operating model—not a government standard. Its purpose is to prevent the employment workflow from issuing sensitive access on the strength of one convincing screen interaction.

1. Define the assurance needed

Classify the role by consequences: access to source code, employee or customer information, finance, payroll, production systems, administrative privileges, regulated data or critical operations. A low-access temporary role and a privileged systems administrator should not require identical proofing.

2. Verify through an independent route

Use lawful evidence and original sources rather than links, numbers or references supplied only by the candidate. Confirm which party performs each check and how results are recorded.

3. Bind the same person across stages

Reconcile the interviewed person, identity evidence, background-check subject, signed employment record, device recipient, enterprise account and payroll destination. Investigate material mismatches before access expands.

4. Separate identity from qualification

Identity proofing asks who the person is. Credential verification asks whether claimed education, licences or employment are accurate. Skills assessment asks whether the person can do the work. Passing one does not answer the others.

5. Gate access

Do not issue sensitive permissions merely because an offer was accepted. Apply least privilege, staged onboarding and additional approval for administrative, financial or employee-data access.

6. Preserve a fair exception path

Legitimate candidates may lack a standard document, require accommodation, have changed names, use assistive technology, live internationally or face a record mismatch. Provide a trained human escalation route rather than automatic rejection.

7. Reverify sensitive changes

Use a trusted channel for bank, payroll, recovery-method, device-destination and privileged-access changes. Do not let a familiar face, voice, email address or chat account substitute for the approved process.

8. Make suspension possible

Define who can pause onboarding, freeze an account, hold payment, preserve evidence and involve HR, security, privacy/legal and leadership when identity concerns remain unresolved.

New-hire access should expand only as confidence and need are established

Hiring fraud becomes organizational compromise when a false or unverified identity receives useful authority. Apply the same principle developed in Benchmark’s guide to autonomous AI and the workplace permission problem: the practical risk is shaped by what the organization permits the actor or system to access, decide, communicate, change or execute.

Create a role-based onboarding profile before the start date. Issue only the applications and data required for initial work. Require separate approval for source repositories, payroll administration, employee records, production environments, payment systems, identity administration and bulk exports. Use phishing-resistant authentication where appropriate; prohibit credential sharing; restrict unauthorized remote-access tools; retain relevant logs; and review access after role changes.

Vendor or staffing arrangements do not transfer the risk. The FBI warns that organizations can be further removed from direct hiring when work is outsourced. Contracts and due diligence should define who verifies workers, what evidence is retained, how substitutions are controlled, where devices are delivered, how access is revoked and how suspicious activity is escalated. Benchmark’s vendor data-risk due-diligence guide provides the broader assessment method.

The identity problem continues after the hire

An organization can verify the original worker and still be deceived later by someone impersonating that employee, an executive or HR. The FBI has documented payroll-diversion tactics involving spoofed employee requests, compromised self-service accounts and changes to direct-deposit information. Voice or video does not eliminate that risk: the Canadian Centre for Cyber Security recommends treating identity signals such as voice and video as untrusted until verified by the organization and using out-of-band verification for sensitive actions.

Require a known, independent route for direct-deposit changes, benefit withdrawals, account recovery, tax-document release and unusual executive requests. Notify the employee through an established channel when sensitive account information changes. Use dual control for high-impact actions and keep the process effective even when the requester claims urgency.

When a payment or data request may be fraudulent, use Benchmark’s Business Email Compromise Response Playbook for HR, Finance and Leadership. It separates transaction stoppage, independent verification, technical containment and possible privacy response.

Stronger verification does not justify collecting everything

Identity evidence can itself become a high-value collection of government identifiers, facial images, voiceprints, addresses and employment records. A badly designed anti-fraud program can reduce one risk while creating a new privacy and breach risk.

NIST SP 800-63A-4 provides a useful risk-based model for digital identity proofing and calls for privacy assessment and data minimization. It was written for digital identity services and is not a universal employment law or a turnkey private-employer policy. Organizations should adapt concepts only after reviewing their context and applicable requirements.

In Canada, the Office of the Privacy Commissioner describes biometric information as potentially sensitive, emphasizes a legitimate need, effectiveness and minimal intrusiveness, and recommends verification rather than broad identification where possible. The OPC also warns that biometrics can be spoofed and that deepfakes or voice synthesis can compromise identities. Applicable federal, provincial, employment, human-rights and sectoral rules differ; U.S. state biometric, privacy, background-check and employment laws can also vary. Obtain jurisdiction-specific advice before deploying biometric or automated verification.

Privacy-respecting design questions

  • Can the same assurance be achieved without biometrics or with a less intrusive method?
  • What exact evidence is needed for this role and risk level?
  • Will the organization retain a document image, a derived template, a verification result or nothing beyond the result?
  • Who can access the evidence, where is it processed, and when is it deleted?
  • What does the vendor retain, reuse for training, disclose or transfer across borders?
  • How will candidates receive notice, provide required consent, request accommodation or challenge an incorrect result?
  • Has the organization tested accuracy, demographic performance, spoof resistance and operational failure modes?

When an identity concern appears, pause and preserve facts

Do not accuse the candidate or worker based on one anomaly. Pause the affected hiring, access, device or payment step; preserve the application, communications, interview records, verification results, account events and device information according to policy; and route the concern to trained HR, security and privacy/legal personnel.

If the person already has access, qualified responders should assess accounts, sessions, devices, repositories, transfers, remote-control tools and information reached. Use proportionate containment, such as restricting access or revoking sessions, without destroying evidence. Keep verified facts separate from assumptions and protect the individual’s confidentiality.

If employee or applicant personal information may have been exposed, connect the event to the organization’s employee data breach response plan and use Benchmark’s U.S. and Canadian breach-notification decision framework. If another person’s identity appears to have been stolen, employee or individual support may become a separate workstream; Benchmark’s employee identity-risk and support playbook explains that distinction.

U.S. organizations can report qualifying suspected internet crime through the FBI’s IC3 and engage appropriate counsel and law enforcement. Canadian organizations can follow their incident process and use appropriate Canadian Anti-Fraud Centre or law-enforcement channels. Reporting a suspected crime does not replace privacy, employment, contractual, insurer or regulatory analysis.

HR owns the doorway, but not the whole control

Recruiting understands candidate experience and hiring workflow. Security understands account, device and threat signals. IT controls provisioning. Privacy/legal assesses collection, monitoring, fairness and jurisdictional requirements. Payroll and finance control money movement. Procurement manages staffing and verification vendors. Leadership sets tolerance and ensures that urgency or seniority cannot bypass the rules.

Assign one accountable owner for the complete identity-to-access process, while preserving specialist decisions. Maintain a data-flow and responsibility map: what evidence enters, who checks it, what vendor receives it, what decision follows, what account is created, what permissions attach and how access is suspended.

This is also an AI-governance issue. Tools that rank applicants, detect liveness, compare faces, flag anomalies or generate risk scores can produce false positives and discriminatory effects. Inventory and assess them under Benchmark’s workplace AI governance framework; do not let an opaque score become an automatic employment decision.

Practical review

Questions organizations should ask now

  1. Which roles create the greatest harm if the worker’s identity is false or controlled by someone else?
  2. At what stage is identity independently verified, and what assurance is proportionate to the role?
  3. Are recruiters treating video appearance, voice or résumé consistency as proof?
  4. Are prior employment, education, licences and references checked through original sources?
  5. Can the organization bind the interviewee, identity evidence, employment record, device recipient, account user and payroll destination?
  6. What material changes during onboarding require re-verification?
  7. Which permissions are issued on day one, and which require additional approval?
  8. How are staffing vendors required to verify workers and control substitutions?
  9. How are bank, payroll, recovery and privileged-access changes independently confirmed?
  10. Can HR quickly reach IT and security when something does not add up?
  11. Who can pause onboarding, access or payment while facts are established?
  12. Are candidates offered notice, accommodation, human review and a path to correct errors?
  13. Is identity evidence minimized, secured, access-controlled and deleted on a justified schedule?
  14. Do incident-response plans cover fraudulent workers, deepfake impersonation, payroll diversion and stolen candidate identities?
  15. Has the organization tested the full workflow—not merely trained recruiters to look for visual glitches?

Use these questions with the Social Engineering & Fraud pillar, the Employee Identity Risk & Support pillar and the wider Benchmark Knowledge Center.

Sources and authoritative guidance

Primary government sources checked for this article are listed below. Threat guidance and laws change; organizations should confirm current requirements and obtain advice appropriate to their circumstances.

Continue with practical governance

Make identity assurance part of hiring, access and fraud prevention.

Explore the connected Social Engineering, AI Governance and Employee Identity resources. The Knowledge Center subscription form is available after the resource library for readers who want future professional guidance.

Explore and subscribe in the Knowledge Center