Deepfake Job Interviews: How Fake Candidates Get Hired in Canada
Deepfake job interviews let fake candidates pass hiring using AI face-swap tools and forged IDs, resumes or references. How Canadian employers can catch it under PIPEDA in 2026.

Summarize this article with
A deepfake job interview is a hiring scam in which the person on the video call is not the person named on the resume. Real-time face-swap software maps a stolen or invented identity onto a live camera feed, while the accompanying paperwork โ a passport or provincial ID scan, a resume, a diploma, sometimes a reference letter โ is forged to match. The goal is almost always a fully remote role, most often in IT, where nobody at the company will ever meet the hire in person.
This is not a fringe curiosity. The US Department of Justice, the FBI and CrowdStrike have documented organized networks running this scheme at scale, and Canadian employers hiring remotely are squarely in scope: in July 2025, the RCMP, Public Safety Canada, Global Affairs Canada, FINTRAC and the Cyber Centre jointly warned Canadian businesses about this exact pattern.
This article is provided for informational purposes and does not constitute legal or regulatory advice. Regulatory references are accurate as of the publication date. Consult your legal team for guidance specific to your situation.
What a deepfake job interview scam actually looks like
A deepfake job interview scam is a live video call where AI face-swap software replaces the applicant's face and sometimes voice with someone else's, so the person answering questions is not the person who will do the job.
The mechanics are cheap to run. An operator buys or steals an identity, builds a resume around it, and either wears a face-swap filter during the interview or has a more articulate colleague sit in for the technical rounds. Voice-authentication firm Pindrop recorded a rise of more than 1,300% in deepfake fraud attempts across contact centres and remote interactions in 2024, from roughly one per month to seven per day (Cyber Daily, February 2025). Recruitment absorbs a share of that volume because a hiring process is built to trust the person in front of the camera.
How fake candidates build a paper trail that survives HR checks
A convincing fake candidate never relies on the video call alone โ the interview is one layer of a forged file that has to hold together across the resume, the ID document and often a reference.
The resume is typically AI-written to match the job description almost too well; the passport or provincial driver's licence is a template forgery or a genuine stolen document; and the reference letter is fabricated because most HR teams still verify it with nothing more than a phone call. CheckFile covers the resume and diploma side in AI-generated CVs and fabricated diplomas, and the reference-letter angle in detecting a fabricated professional reference. CrowdStrike found that the group it tracks as Famous Chollima had built entire fake companies, complete with AI-generated websites, GitHub profiles and email infrastructure, to backstop these applications (CyberScoop, 2026).
The identity and document layers are meant to reinforce each other: if the interviewer gets suspicious about the video, the forged ID and the plausible reference reassure the recruiter that "the paperwork checks out."
The North Korean remote IT worker scheme Canadian authorities are tracking
The dominant documented case of this fraud pattern is a state-linked operation using stolen Western identities to get North Korean IT workers hired into remote technical roles, and Canada is named directly in the government response. On July 18, 2025, the Cyber Centre, the RCMP, Public Safety Canada, Global Affairs Canada and FINTRAC warned that operatives use "AI-enabled deepfake technology which disguise appearances" to pass interviews for remote IT roles, flagging crypto payment requests and video-call reluctance as red flags (Canadian Centre for Cyber Security, July 2025); FINTRAC co-signed because salaries paid to a fraudulent hire can finance a UN-sanctioned weapons program. Canada renewed the warning a year later alongside ten other governments (US Department of State, July 2026).
The FBI's wanted notice describes the mechanics: operatives use stolen or fabricated identities, apply through ordinary job boards, and sometimes have a different, more technically fluent person sit the interview than the one who does the day-to-day work (FBI, Fraudulent Remote IT Workers from DPRK). Company laptops are shipped to a residential address, plugged into a "laptop farm," and accessed remotely so the login traffic looks domestic. The Department of Justice's coordinated 2024 enforcement actions describe a scheme using the stolen identities of at least 80 US persons that generated more than $5 million for the North Korean government (DOJ, Two US Nationals Sentenced; DOJ, Coordinated Nationwide Actions).
The best-known single incident is security vendor KnowBe4's own admission that it hired one of these operatives in July 2024. The candidate passed several rounds of video interviews and a background check using a stolen US identity, and was only caught after the new "software engineer" loaded malware onto a company laptop within minutes of receiving it; KnowBe4 shut off access 25 minutes later (KnowBe4, How a North Korean Fake IT Worker Tried to Infiltrate Us) โ a cybersecurity vendor with a full security stack still let it through the interview stage.
Ready to automate your checks?
Free pilot with your own documents. Results in 48h.
Request a free pilotReal candidate or deepfake โ what to look for on the call
The clearest tell during a live interview is what happens when the candidate moves unpredictably in front of the camera: most consumer-grade face-swap filters cannot track a hand or object passing in front of a face without glitching.
Dawid Moczadลo, co-founder of Vidoc Security Lab, described exactly this in an account picked up by The Register: a candidate's face blurred and distorted on a Zoom call, and asking him to wave a hand across his own face broke the filter and exposed the swap (The Register, February 2025). That test is now widely used as a quick, low-cost screen, though it is not the only signal worth checking.
| Signal | Genuine candidate | Likely deepfake or proxy interview |
|---|---|---|
| Hand or object passed in front of face | Face stays sharp and consistent | Edges blur, flicker, or briefly reveal a different face |
| Head turned fully to profile | Features remain proportional | Face geometry distorts or the filter drops out |
| Sudden, unscripted question | Natural pause, then a direct answer | Long delay, generic answer, or the "candidate" reroutes to a script |
| Lighting change (candidate moves near a window) | Skin tone and shadows shift naturally | Face lighting stays static while the background changes |
| Audio-lip sync during rapid speech | Sync holds under fast talking | Micro-delays or mismatched mouth shapes appear |
| Requested live task (screen share, live code, handwriting) | Completes it visibly, in real time | Resists, stalls, or hands off to "connection issues" |
What this means for Canadian employers hiring remote
A Canadian employer that unknowingly hires a fraudulent remote worker may have handed system or customer-data access to someone it cannot identify, which is a live PIPEDA problem, not a hypothetical one. The OPC's guidance on identification and authentication expects organizations to verify identity in proportion to the access being granted (OPC, Guidelines for Identification and Authentication), and a fraudulent hire who exfiltrates data triggers PIPEDA's mandatory breach-reporting duty. That federal floor is not uniform: Quebec's Loi 25 adds mandatory privacy impact assessments and its own breach rules, and Alberta and BC run their own "substantially similar" statutes, so a multi-province program must clear the strictest layer.
The Canadian Anti-Fraud Centre recorded more than $49 million CAD in reported losses to job and employment scams in 2024, roughly quadruple the 2022 total (Canadian Anti-Fraud Centre data, reported by Daily Hive, 2025). Fully remote IT and software roles โ the focus of our staffing and recruitment solution โ remain the most targeted category, because nobody expects to meet the hire face to face. Employers also carry a parallel duty to confirm work authorization; a forged permanent resident card or work permit alongside a deepfaked interview is the same fraud pattern, aimed at IRCC's check instead of the identity check.
A verification checklist before you extend an offer
The most effective control is not a clever question on the call โ it is checking that the identity, the documents and the interview all describe the same person before an offer goes out.
- Verify the ID document itself (structure, fonts, security features, MRZ checksum on a passport), not just a photo of it.
- Cross-check the resume's claimed employer against a reference contacted through a switchboard number you look up independently, not one supplied by the candidate.
- Ask for one unscheduled, camera-on task in a later round โ live coding, a screen share, a document held to the camera.
- Confirm bank and next-of-kin details provided at onboarding match the verified identity, not a third party.
- Treat resistance to a second, unscheduled video call as a flag worth escalating.
Manual reference and document checks alone are not a reliable backstop. Per the ACFE's 2024 Report to the Nations, only 37% of document fraud is caught by internal manual controls, with a median detection delay of 87 days โ long enough for a fraudulent hire to be fully onboarded and granted system access (ACFE, Report to the Nations 2024).
Where CheckFile fits in a remote hiring workflow
CheckFile does not replace the hand-wave test or a properly sourced reference call โ it checks the documents a fake candidate still has to submit even when the face on the call is AI-generated. Our platform analyzes the ID document, the resume and any diploma or reference letter attached to the same candidate file against each other for structural and metadata inconsistencies, with AI-generated content forensics available as an optional layer. In practice, that means detection grounded in multi-layer analysis of the ID, the CV and the diploma or reference letter attached to the same file, rather than a judgement call made on video alone. The same logic applies to a forged provincial driver's licence or the synthetic and templated identity documents used in this scam โ a complement to existing controls, not a replacement for them.
If remote hiring is a meaningful share of your recruitment volume, our deepfake detection module is built for this scenario, alongside the broader document security controls underpinning the platform. Pricing scales with volume rather than headcount on our plans page; teams evaluating fit across sectors can start from our industry verification guide, or see the full product on the CheckFile homepage.
Frequently Asked Questions
Does asking a candidate to wave their hand in front of their face actually detect a deepfake?
It catches many consumer-grade real-time face-swap filters, which struggle to render an object passing in front of a tracked face without glitching. It is not foolproof against higher-quality software, so treat it as one signal among several.
How common is this, really, or is it mostly a North Korea-specific problem?
The North Korean scheme documented by the FBI, DOJ and the Cyber Centre's 2025 advisory is the largest known organized version, but the underlying face-swap tools are consumer-grade, so opportunistic fraud โ someone else sitting a technical interview for a friend โ uses the same techniques on a smaller scale.
What should we do if we suspect we already hired someone using this method?
Restrict system and data access immediately rather than waiting to build a full case, following the same logic KnowBe4 applied when it cut a new hire's access within 25 minutes. Preserve laptop and login logs, involve legal and security before any confrontation, and report the case to the Canadian Anti-Fraud Centre and, if sanctions evasion is suspected, the RCMP.
Can document verification software alone stop a deepfake interview scam?
No single tool closes this gap alone, because the scam defeats several checks at once โ the interview, the ID and the reference. CheckFile adds a layer that checks the paperwork for inconsistencies a recruiter is unlikely to spot manually, but it works best combined with live interview scrutiny and independent reference checks.
Is this only a problem for IT and tech roles?
IT and software roles are the most reported category because they are easiest to perform fully remotely with no physical deliverables, but CrowdStrike has noted the same networks branching into customer support and sales. Any fully remote position with system access carries the same risk, regardless of job title.
Stay informed
Get our compliance insights and practical guides delivered to your inbox.