Skip to content
Blog

Craft

One candidate profile in four will be fake by 2028

Gartner expects one profile in four to be fake by 2028, and half of applications to remote IT roles. 41 % of companies have already hired one.

By moving the check to the moment it commits something, meaning before signature and before access to your client’s systems, rather than at application where it protects nothing. The check that counts is not the first one in the process, it is the last one before a door opens.

The scale of this changed by an order of magnitude in eighteen months. Gartner expects one candidate profile in four to be fake or synthetic by 2028, and at least half of the applications received for remote IT roles to be false already. Across 19,368 live interviews analysed between July 2025 and January 2026, 38.5 % showed concealed assistance.

Who these numbers actually apply to

They are not evenly spread, and the gap is what makes this urgent for a staffing firm rather than for companies in general. The rate reaches 48 % on software engineering roles and falls to 12 % on sales roles, which follows exactly the line between what is assessed by a remote technical exercise and what is assessed by a conversation.

The second factor is distance. An on-site role with a face-to-face interview closes most fraud scenarios through the geometry of the situation, whereas a fully remote role, paid in hard currency, with access to a code repository, is precisely the target the reports describe.

The third is speed. Fast processes, where you are trying to place somebody within ten days because the client is waiting, are the ones where reference checks get skipped and where a recorded technical interview is accepted instead of a live one. Commercial pressure and attack surface grow together.

Why a staffing firm is doubly exposed

Because it does not hire only for itself. A direct employer who hires a fake profile suffers a bad hire, which is expensive and repairable; a staffing firm that places that profile at a client has put an unidentified person inside a third party’s information system, under a contract it signed and answers for.

The confidentiality clause you negotiated with that client assumes you know who works for you. That is a contractual assumption, and 41 % of companies have already hired a fraudulent candidate without noticing, which means the assumption is false more often than the industry admits.

There is a commercial consequence almost nobody anticipates. The day a client finds out, they do not blame you for having been deceived, they blame you for having had no procedure. The question that arrives is “show me how you verify”, and an improvised answer costs the whole account.

What automatic detection does not solve

Only 31 % of companies have deployed a detection tool, and that figure is usually presented as the problem. It is more accurately the symptom of a sound instinct: software that scores the probability of a synthetic face answers the question of image forgery, not the question of who does the work.

The two most common scenarios are in fact entirely unspectacular. A real person sits the interview for another, who will take the job; or a real person sits the interview while being coached live, which leaves a perfectly authentic image. No deepfake detector sees either, and 61 % of the candidates identified as cheating had cleared the pass thresholds.

The argument is worth stating plainly, because it comes up in every conversation on the subject. Adding a layer of AI to detect AI-assisted fraud is the natural reflex, and it is the same reflex that produced the loop in which both sides arm themselves and information quality falls on both. The way out is not in escalation.

The three moments where verification earns its cost

At the technical interview, live, with follow-up questions. An asynchronous exercise measures what the candidate, or their assistant, produced. A conversation in which you ask why a given decision was taken, then what would happen if the constraint changed, measures what the person understands, and that is very hard to simulate in real time.

At reference checks, on a number you found yourself. A contact supplied by the candidate proves they know somebody who will answer. A company called through its switchboard, where you ask to speak to a former manager, proves something else, and it takes fifteen minutes.

At signature, with formal identity verification. That is the moment it is needed anyway, where it surprises nobody, and where it genuinely protects, since it sits just before access opens. Placed there, it costs little and closes the most serious scenario.

These three checks share one property that has to be owned: they take human time, and they take it exactly where commercial pressure pushes you to save it. That is a management trade-off, not a tooling decision.

The scenario nobody prepares for

The expensive case is not the one caught at interview, it is the one discovered after the assignment has started. Somebody has been working at your client for six weeks, deliverables are arriving, and one detail eventually fails to line up: a time zone that does not match the declared address, a camera always switched off, an invoice heading for a country nobody had mentioned.

What makes that moment hard is that there is almost never a procedure. The person who spots the anomaly does not know who to tell, management hesitates between warning the client and checking first, and the access stays open throughout. The delay between doubt and decision is the only variable that matters, and it is settled by design, before the incident.

So decide three things now, while the question is still theoretical. Who receives the report, what is suspended immediately and what is not, and when the client is told. The right answer to the third is almost always “straight away”, because the reproach that costs the account is not having been deceived, it is having waited to understand before saying so.

Note finally that suspending an access is not an accusation, and it has to be framed that way internally. Conflating the two is what pushes teams to hold a report back until they are certain, which is to say until the measure can no longer do any good.

What not to do along the way

The temptation, facing these figures, is to apply a biometric check to every application. It is a bad idea on three counts, and the legal one is not the first.

The first is effectiveness: a check applied to everyone at the least committing moment of the process simply displaces the fraud effort, while adding friction your real candidates absorb. The second is reputation, in a market where a candidate who finds the process demeaning leaves without saying so. The third is the legal frame: biometric processing for identification purposes needs a solid legal basis and an impact assessment, and it does not get improvised because a vendor gave a convincing demo.

The rule that holds is the same as everywhere else on this blog: a check belongs where it closes a door, and a decision that closes a door stays human. None of this automates without somebody validating, and that is even truer when the conclusion of the check is an accusation.

What this changes about the interview itself

The most interesting shift is that fraud has restored the value of what the industry had started to abandon. The live interview, the unplanned follow-up question, the reference call made properly: these expensive gestures were being replaced by automated assessments, and they are becoming the only reliable measure again.

It is good news in poor clothing. The process that resists fraud is also the one that evaluates best, because it rests on a conversation in which somebody has to explain what they did. What remains is finding the time, which means saving it elsewhere, and that is exactly the work you can delegate without risking anything: the write-ups, the follow-ups, the record updates.

Frequently asked questions

Does deepfake detection software solve the problem?

It catches some of it and lets some through, including at companies that have deployed one. Gartner in fact expects 30 % of organisations to find their identity tools unreliable against deepfakes this year. Detection is a safety net, never the main measure.

When should identity be verified?

As late as possible and before anything is committed, which means before signature and before access to the client’s systems. Verifying at application costs money, irritates real candidates and protects nothing, since the fraud plays out at the technical interview and at hiring.

Can you ask a candidate for identity documents?

For a hire, identity verification is legitimate at the point of engagement, where it is required anyway. Asking for it early in the process, retaining it, and processing it through a biometric system are three separate decisions, each needing a legal basis and the third an impact assessment.

Which signals cost nothing to check?

Consistency between the career as told and the career as written, a reference called on a number you found yourself, and a technical exercise run live with follow-up questions. None of the three needs a tool, and all three need human time.

Sources

  1. The Interview Guys, The state of hiring fraud 2026, July 2026blog.theinterviewguys.com
  2. The Hacker News, Deepfake job hires: when your next breach starts with an interview, January 2026thehackernews.com
  3. CNBC, How deepfake AI job applicants are stealing remote workcnbc.com

Read next

€100 in credits when you sign up

Join the waitlist.

Leave your email address and we will let you know as soon as Balt can join your team.

Already 247 staffing firms on the waitlist