Deepfake and proxy candidate detection in remote interviews (2026)
Sep 15, 2026
Deepfake and proxy candidate detection: what the software can and can't do
We sell some of this software, so start from the most inconvenient fact we know.
There's a widely quoted case that gets used to sell every product in this category: the Hong Kong finance worker who transferred about $25 million after a video call with what appeared to be his CFO and several colleagues. All of them fake. Arup confirmed in May 2024 that they were the company involved.
What the case doesn't show is the thing people cite it for. Acting Senior Superintendent Baron Chan of the Hong Kong Police told reporters in February 2024 that "the deepfake videos were pre-recorded and did not involve dialogue or interaction with the victim." The attackers pulled public video and audio from YouTube. Nobody on that call was responding in real time.
It's a payment fraud case, not a hiring case, and it isn't evidence of real-time interactive deepfake capability. If a vendor opens with Arup, they're either not reading carefully or hoping you won't.
The threat is real and is mostly not deepfakes. The US Department of Justice's December 2024 indictment of fourteen North Korean nationals describes the core tactic as "paying U.S. persons to attend job interviews and work meetings remotely under fake identities." A real human proxy, paid to sit the interview. That scheme produced $88 million over roughly six years. In June 2025 the DOJ announced coordinated actions covering more than 100 US companies, 21 laptop farms across 14 states, and around 137 laptops seized. In November 2025 a further action put the count at 136 plus companies.
Video interviews don't stop it. KnowBe4 published their own account in July 2024: four video interviews, the person matched the application photo, they hired the operative. The photo was an AI-enhanced stock image over a stolen but genuine identity, which is also why the background check passed.
Deepfakes in interviews are documented but less common. The FBI's IC3 alert I-062822-PSA, issued 28 June 2022, is the original warning, and the signal it names is the useful one: "the actions and lip movement of the person seen interviewed on-camera do not completely coordinate with the audio of the person speaking." Two 2025 cases were reported in detail. Dawid Moczadło at Vidoc Security Lab encountered deepfaked candidates twice, reporting that "the person wasn't moving like a person," head and neck misalignment, and a synthetic face failing to composite correctly with real hands. A recruiting lead at Make described a candidate whose eye and mouth movements were out of sync and whose face edges distorted, who disconnected 30 seconds after being asked to wave a hand in front of their face.
The self-reported numbers. Gartner surveyed 3,000 candidates in 2025 and 6 percent admitted to interview fraud, either posing as someone else or having someone pose as them. A Greenhouse survey published in November 2025 found 65 percent of hiring managers had caught applicants using AI deceptively: 32 percent reading from AI generated scripts, 22 percent hiding prompt injections in resumes, and 18 percent showing up as deepfakes.
Attack tooling is getting cheaper fast. iProov reported native virtual camera attacks up 2,665 percent, and face swap attacks up 300 percent against 2023, alongside roughly 24,000 users identified across crime-as-a-service groups selling the tooling. iProov sells the countermeasure, so weigh it accordingly, but the direction is consistent with what the DOJ and CrowdStrike report.
Two numbers we'd avoid. Fortune reported in April 2025 that Pindrop found roughly 12.5 percent of applicants fake, though that was about 100 of 827 applications for one senior back-end developer role, and Pindrop sells deepfake detection. A single requisition is not an industry rate. And there is no credible published figure for proxy interview rates in India specifically. We looked hard. What exists is background verification discrepancy data, which measures resume and employment falsification: AuthBridge puts IT and ITeS at 9.46 percent and BFSI at 11.69 percent for October 2024 to March 2025. Those are different things. If you see a percentage claimed for Indian proxy interviews, assume it's invented until someone shows you the study.
The two attack types vendors conflate
This distinction decides whether a certification means anything.
A presentation attack puts something in front of the camera: a printed photo, a phone screen, a silicone mask. This is what ISO/IEC 30107-3 covers and what iBeta tests. Level 1 caps artefact cost at $30 and allows a 0 percent penetration rate. Level 2 allows artefacts up to $300, including 3D printed and resin masks, with up to 1 percent penetration.
An injection attack never passes a lens. Synthetic video is fed straight into the pipeline through a virtual camera driver. The camera sees nothing because the camera isn't involved.
iBeta's published methodology describes presentation attacks. A vendor telling you they're iBeta Level 2 certified has demonstrated resistance to masks and printouts, which is worth something, and has not demonstrated resistance to a deepfake injected into a Zoom call. Those are different problems requiring different signals, and the certification does not bridge them. Ask specifically.
What actually detects each thing
Face matching against a trusted reference. NIST's August 2025 work on morph detection makes the case for structure over cleverness. Detecting a manipulated face from a single image reaches near 100 percent when the detector was trained on the same generation software, and falls to "well below 40 percent" against software it hasn't seen. Differential detection, comparing against a trusted reference image, runs 72 to 90 percent and holds up far better across unfamiliar tools. Capture a reference at application and compare every session against it.
Lip sync and audio-visual consistency analysis. The highest value signal, for a reason that's measurable. A 2025 systematic review of the research reports one study in which humans detected face swaps at 91.3 percent and lip sync deepfakes at 52.6 percent, which is a coin flip. A real face driven by synthesised speech is the attack humans are worst at, and it's the shape most video interview deepfakes take. Automation adds most where people add least.
Liveness detection, ideally 3D. Confirming a real three dimensional person rather than a flat surface. Necessary, not sufficient, and the published research is candid about why: liveness techniques "may fall short when confronted with sophisticated video injection scenarios, where the spoofed content convincingly mimics live behavior."
Virtual camera and device signals. The only class of signal that directly addresses injection. One published method doesn't analyse the image at all: it requests unusual frame heights and frame rates from the camera and measures how fast the device responds. Physical hardware takes time to reconfigure, virtual cameras respond in software. See the next section for what that costs.
Voice verification. Cross-checking vocal patterns against earlier interactions. The ASVspoof 5 evaluation found anti-spoofing performance degrades under adversarial attack and under neural encoding and compression, which is what every video conferencing platform applies to every call. Clean-audio accuracy doesn't transfer.
Active challenge-response. The FBI's July 2025 guidance recommends mandating unobscured backgrounds, having candidates point the camera out a window and answer questions about their location, and asking them to wave a hand in front of their face, which "may prompt a malfunction in AI generated video." It's free, processes no biometrics and worked in three of the four documented cases above. It's also a 2026-era weakness, not a permanent one. Occlusion handling improves with each model generation.
The number vendors don't put on the slide
Published research on virtual camera detection reports AUC above 0.9, which sounds excellent. The operating points are the story:
Injection attacks caught
Genuine candidates wrongly rejected
90 percent
14.6 percent
99 percent
68.3 percent
99.9 percent
91.7 percent
One method, one paper, and other systems will differ. The shape won't. High detection rates in this category are bought with false rejections, and a vendor quoting one without the other is showing you half a table.
Hiring is the worst domain for this trade-off. A false positive in payments is a declined card. A false positive in hiring is a qualified person told they cheated, and depending on who they are and how the errors distribute, a discrimination complaint.
There's a second reason to keep a human in the loop. Deepfake-Eval-2024, a benchmark built from deepfakes actually circulating online rather than lab-generated ones, found detector AUC dropped by about 50 percent for video, 48 percent for audio and 45 percent for images against previous benchmarks. Commercial and fine-tuned models beat off-the-shelf open source ones and still "do not yet reach the accuracy of deepfake forensic analysts." Expect a vendor's benchmark number to degrade substantially on your candidates, and ask them what it degrades to.
What vendors actually claim, checked in September 2026
We read every one of these on the vendor's own pages.
HirePro publishes the most detailed spec in the category: 30 plus fraud signals, including real time detection of deepfakes, virtual cameras, recorded feeds and stand-ins, unauthorised AI assistance identified through content, style, speech patterns and typing analysis, government ID matched to face and name and rechecked during the interview, and mid session identity switch detection. No published methodology behind any of it.
InCruiter claims dual voice detection, detection of altered videos, face swap attempts and AI generated voices, eye movement tracking and multiple faces in frame, rolled into a risk score on the report.
BerriBot, ours: Berri Proctor detects micro-signals through 3D liveness detection and lip sync analysis, alongside identity verification, environment analysis and behavioural monitoring. Smart glasses detection was added in January 2026 after training our vision systems on the publicly available Meta Ray-Ban devices, and the flag behaviour is documented: immediate flag, candidate warned, interviewer notified. We published that with a caveat we'll repeat here: no detection system is 100 percent foolproof, and anyone claiming otherwise is lying. We also don't publish a false positive rate, which by the standard of this article is a fair thing to hold against us.
Talview markets against "deepfake identities bypassing verification" and "proxy test-taker networks" on their homepage and claims a 99.9 percent fraud detection rate with no published methodology. Their Candidate Verification page names face matching, voice verification, multi-face and no-face detection, device and connection monitoring, and ID checks against third party and AML databases. It does not name deepfake detection. Identity verification is also a separate product from their AI interviewer rather than built into it.
iMocha handles impersonation through government ID and selfie verification in about 10 seconds, face detection for unrecognised, multiple or absent faces, a cheating intensity rating and virtual machine detection. No deepfake claim.
Eklavvya claims face recognition identity verification, multi-face detection, device detection and anti-LLM prevention, and is the only vendor we found naming specific Indian languages.
HackerRank and HackerEarth claim no identity verification and no deepfake detection. HackerRank's own writing names candidate impersonation as an industry problem without claiming to solve it, which we'd rather see than a vague claim.
HireVue lists cheating and fraud mitigation among its features without publishing detection specifics.
None of these vendors, ours included, publishes a false positive rate. None publishes methodology. Treat every number above as a marketing claim until it survives your own pilot.
Eight questions that separate capability from marketing
Ask every vendor these, in writing, and compare the answers rather than the demos.
Does your detection cover injection attacks through a virtual camera, or only presentation attacks? If you cite an iBeta certification, which level and what was in scope?
What's your false rejection rate for genuine candidates at the detection rate you just quoted?
Which specific signal catches a lip-synced deepfake, as distinct from a face swap?
Do the checks run during the live interview, or on a recording afterwards?
What does the interviewer see, and when, after a signal fires?
Who reviews a flag before any decision, and what does the candidate get told?
Has your detection been tested on deepfakes generated by tools it wasn't trained on? What happened to accuracy?
Which AWS or Azure region does our candidates' biometric data sit in, and what's the retention period?
The second question is the one that does the most work. In our experience, how a vendor answers it tells you more about the product than any feature list.
FAQ
Can software detect a deepfake in a job interview?
Partially, and less reliably than vendors suggest. Lip sync and audio-visual consistency analysis is the strongest signal, because it targets the attack humans are worst at: humans detect lip sync deepfakes at around 52.6 percent accuracy against 91.3 percent for face swaps. Detector performance drops sharply on deepfakes circulating in the wild compared with lab benchmarks, with one benchmark reporting AUC falling about 50 percent for video, and no commercial model has matched human forensic analysts. Detection narrows the field and should trigger human review rather than automatic rejection.
What's the difference between a presentation attack and an injection attack?
A presentation attack shows something to the camera, like a printed photo, a screen or a mask. An injection attack feeds synthetic video directly into the pipeline through a virtual camera driver, so no camera is involved. ISO/IEC 30107-3 and iBeta certification cover presentation attacks. Injection attacks require different signals, typically device and camera reconfiguration timing, and are not covered by that certification.
How common are proxy candidates and deepfakes in interviews?
Gartner's 2025 survey of 3,000 candidates found 6 percent admitted to interview fraud, which as a self-reported figure is a floor. A Greenhouse survey published in November 2025 found 65 percent of hiring managers had caught applicants using AI deceptively, with 18 percent saying a candidate had shown up as a deepfake. The US Department of Justice has documented North Korean schemes affecting more than 100 US companies, using paid human proxies to sit interviews under stolen identities. No credible figure exists for proxy interview rates in India specifically.
Which interview platforms detect deepfakes?
As of September 2026, HirePro publishes the most detailed claim, covering deepfakes, virtual cameras, recorded feeds and stand-ins across 30 plus signals. InCruiter claims face swap and AI generated voice detection with a risk score. BerriBot runs 3D liveness and lip sync analysis during the interview. Talview markets against deepfake identities at the platform level without naming deepfake detection on its Candidate Verification page. HackerRank, HackerEarth and HireVue publish no deepfake detection claim. No vendor publishes methodology or false positive rates.
Does the Arup $25 million deepfake case prove AI can fake a live interview?
No, and it's frequently misused. Hong Kong police stated that the deepfake videos in that case were pre-recorded and did not involve dialogue or interaction with the victim. The attackers used public YouTube footage. It's a payment fraud case rather than a hiring one, and it does not demonstrate real-time interactive deepfake capability.
What is the false positive risk of deepfake detection in hiring?
Significant, and under-disclosed. Published research on virtual camera detection reports that catching 99 percent of injection attacks at that operating point rejects roughly 68 percent of genuine users, and catching 99.9 percent rejects about 92 percent. Numbers vary by system but the trade-off is structural. In hiring, a false positive means a qualified candidate accused of cheating, so ask for false rejection rates alongside every detection rate.