Candidate fraud — also called applicant fraud, and part of the broader category of hiring fraud — is any material misrepresentation a job applicant makes to win a role: a fabricated employment history, a borrowed or stolen identity, a proxy sitting the technical interview, or a reference who was never a colleague. The category spans everything from a padded job title to organized infiltration by state-sponsored operators, and what has changed isn't that candidates misrepresent themselves. It's that convincing misrepresentation now costs almost nothing to produce.
Gartner predicts that one in four candidate profiles worldwide will be fake by 2028. That forecast reframes candidate fraud from an occasional bad hire into a screening-design problem, and it isn't only a forecast: in the same research, 6% of 3,000 candidates surveyed admitted to interview fraud, either posing as someone else or having someone else pose as them.
TL;DR
Candidate fraud has five distinct types: resume and credential misrepresentation, fake references, interview fraud (proxies and deepfakes), identity fraud, and organized infiltration rings. They fail different screening layers, so no single tool catches them all: resume screening catches almost nothing, interviews catch less than they used to, and identity verification confirms a person exists without confirming their history. The layer that resolves the largest share is the oldest one — contacting the previous employer and the references directly to confirm the claimed history is real.
The Five Types of Candidate Fraud

1. Resume and credential misrepresentation
The baseline and by far the most common: inflated titles, stretched employment dates that paper over gaps, responsibilities borrowed from a manager's job description, degrees never completed, certifications never earned. It is also routine rather than exotic: in HireRight's 2025 global benchmark survey of over 1,100 HR and screening professionals, more than three in four respondents said background screening had surfaced a discrepancy in the previous twelve months. Generative AI didn't invent any of this, but it removed the two things that used to limit it: the effort of writing a convincing history and the tell of inconsistent prose. We cover the mechanics in why your hiring process can't catch AI resume fraud.
2. Fake references
A reference who is a friend, a relative, or a paid service reading from a script. This is the most under-examined type, because reference checks are often treated as a formality run at the end of a process where the decision has already been made. It's also the one where the fraud is cheapest: a phone number the candidate supplies, answered by someone the candidate chose.
There is a commercial industry serving this. Services like CareerExcuse, which has operated openly since 2009, sell packages in which staff answer the phone as a former supervisor or HR department, with a registered company, a website, company email, and a LinkedIn page behind it. Its published tiers start around $400 and explicitly list "Verification of Employment (HR)" and a written VOE on company letterhead as line items. Read that carefully: the product being sold is a successful outcome to the exact call a screening team makes.
3. Interview fraud: proxies, deepfakes, and AI assistance
Someone other than the candidate answers the questions: a proxy on camera, a real-time AI assistant feeding answers, or increasingly a synthetic face and voice over a video call. The interview was the control that everything else in hiring implicitly trusted, and it no longer carries that weight on its own. See why you can't trust the video interview anymore.
4. Identity fraud
The candidate is not who they claim to be at all: a stolen identity, a synthetic one assembled from real and invented details, or a legitimate person acting as a front for someone who couldn't pass screening. This is a distinct problem from misrepresentation, and it needs a distinct control: identity verification, which confirms a real person exists behind the application but says nothing about whether their work history is true. In the same HireRight survey, roughly one in six employers said they had already experienced identity fraud during hiring, and another three in ten didn't know whether they had — while only about three in five said they run identity checks at all.
5. Organized infiltration rings
The industrial version: coordinated operations that place multiple fraudulent candidates across many employers, sometimes with the same fabricated employer histories and the same references vouching for each other. The state-sponsored variant is the documented extreme. In July 2025 an Arizona woman was sentenced to 102 months for running a "laptop farm" that helped overseas IT workers pose as U.S. employees: 68 stolen American identities, 309 U.S. businesses defrauded, and at least $17.1 million generated. A coordinated DOJ sweep searched 29 suspected laptop farms across 16 states. The mechanics are the same as the individual case; only the scale and the intent differ.

The most instructive public case is one a security company published about itself. In 2024, KnowBe4 hired a North Korean operative for an internal IT role. The candidate cleared four video interviews and a background check, because the identity being used was a real one that had been stolen and the photo was an AI-enhanced stock image. Malware loaded onto the workstation within minutes of it being provisioned. Four interviews and a clean background check, and the process still failed — which is the argument for treating any single control as insufficient.
Why Candidate Fraud Is Rising
Three shifts compounded, and none of them are reversing.
Remote hiring removed the physical checkpoints. A process that once involved a building, a badge, and a person in a room is now a video call and a DocuSign. Every implicit verification that came from physical presence disappeared, and nothing replaced it by default.
The cost of a convincing lie collapsed. Fabricating a coherent work history, a matching LinkedIn presence, and a professional-sounding reference used to take real effort and some skill. Now it takes a subscription and an afternoon.
Screening never moved. Most hiring processes still verify at the end, after the offer, because that's where verification has always sat for cost reasons. That sequencing means the fraud, if it's caught at all, is caught after weeks of interviewing time have been spent — which is the argument for moving verification earlier in the hiring cycle.
How to Detect Candidate Fraud: Which Layer Catches What

Detecting candidate fraud is less about buying a detection product than about knowing what each control you already run can and cannot identify. The practical failure in most hiring stacks isn't a missing tool; it's that each layer is quietly assumed to cover more than it does.
| Layer | Catches | Misses |
|---|---|---|
| Resume screening / ATS | Obvious inconsistencies | Everything internally consistent, which AI-written resumes reliably are |
| Interview | Candidates who can't do the job | Proxies, real-time AI assistance, well-coached deepfakes |
| Identity verification | Many stolen and synthetic identities | Whether a real, verified person's stated history is true |
| Criminal records search | Adjudicable records | Fabricated employment and education entirely (a bundled "background check" may add verification — the three are different products) |
| Employment and reference verification | Fabricated employers, inflated titles, invented dates, fake references | Fraud at employers that confirm anything asked, and non-responsive employers |
Read down the "misses" column and one pattern stands out: four of the five layers can be fully satisfied by a candidate whose entire work history is invented. The only layer that tests the history itself is the one that contacts the people who would know.
Preventing Candidate Fraud: The Sequence That Works
Prevention is less about adding tools than about ordering the ones you have so each catches what the previous one can't.
- Define what must be true. Which claims actually drive the hiring decision (employment dates, title, a specific credential)? Verify those; skip the rest. A verification policy applied inconsistently is both a fraud gap and a fairness problem.
- Verify identity early, separately from history. Identity verification and history verification answer different questions. Running one and assuming it covered the other is the most common structural error in screening design.
- Move employment verification before the offer, not after. The point of verification is to inform the decision, and a result that arrives after the offer letter is documentation rather than a check. Our guide to verification before the offer covers the FCRA and timing considerations.
- Source contact information independently. Never use a phone number the candidate supplied for the employer or the reference. This single discipline defeats most fake-employer and fake-reference schemes, and it's covered in which department to call for employment verification.
- Ask references questions that require having worked together. Scope of responsibility, working relationship, re-hire eligibility. A coached friend handles "was she good?" and struggles with "what did she own on that project, and who did she report to?" Our reference check questions guide has the full set.
- Run it inside the FCRA rules. Where a third party performs the check, that's a consumer report: standalone written disclosure, signed authorization, and the pre-adverse and adverse-action sequence if a result costs someone the role. Applying the process unevenly is where both compliance and fairness problems start.
- Document every attempt. What was checked, when, through which channel, and what came back, for every candidate rather than just the suspicious ones.
Where Superunit Fits: Verifying the History Itself
Superunit is the verification layer in that sequence. Its AI agents research the employer's or reference's contact information independently rather than relying on the details supplied on the application, then call, email, and fax in parallel, re-attempting across business hours to reach a person who can confirm employment, title, dates, and where the employer discloses it, income. On reference checks specifically, the same agents conduct structured interviews rather than sending a form.
What that catches is the fraud that survives everything upstream: the employer that doesn't exist, the title that was two levels lower, the eighteen months that were really six, the reference who turns out to be a personal friend rather than a former manager. On reference checks specifically, that approach completes 83% of checks with a median turnaround of about three hours. Superunit has completed more than 200,000 verifications across hiring, lending, and screening; the mechanics are on the employment verification product page.
What Superunit Does and Doesn't Cover
Being precise about scope matters more than a broad claim here. Superunit verifies history: employment, references, education (high school and trade school), and DOT records. It is not an identity verification product, and it does not screen resumes for AI authorship. Those are separate controls with separate vendors, and a screening stack needs them alongside verification rather than instead of it. If a vendor tells you one product covers all five fraud types in the table above, that's the claim to interrogate.
Frequently Asked Questions
What is candidate fraud? Any material misrepresentation made by a job applicant to obtain employment: fabricated or inflated work history, false credentials, fake references, a proxy or deepfake in the interview, or a stolen or synthetic identity. It's distinct from recruitment fraud, which refers to scams committed against job seekers.
How common is candidate fraud? Gartner projects one in four candidate profiles worldwide will be fake by 2028. Measured figures sit lower than the projection but are still substantial: 6% of candidates in Gartner's 2025 survey admitted to interview fraud outright, and more than three in four employers in HireRight's benchmark found a screening discrepancy within a year. Prevalence varies by role, seniority, and hiring channel.
How do you detect candidate fraud? No single detection method identifies every type. Identity verification catches stolen and synthetic identities; interview controls catch some proxies; document analysis catches fabricated credentials. Fabricated employment history is caught by contacting previous employers directly at independently sourced contact information.
How do you prevent candidate fraud? Sequence the controls: define which claims matter, verify identity and history as separate steps, move employment verification before the offer, source all contact details independently, ask references questions that require genuine working knowledge, and document every attempt uniformly across candidates.
What's the difference between candidate fraud and identity fraud? Identity fraud is one type of candidate fraud, where the applicant isn't who they claim to be. The broader category also covers applicants who are exactly who they say they are but have misrepresented what they've done.
Is candidate fraud illegal? Misrepresentation on an application is generally grounds for rescinding an offer or terminating employment. Whether it rises to a criminal matter depends on the jurisdiction and what was falsified — forged credentials, stolen identities, and organized schemes carry materially different exposure than an inflated job title. Employment counsel should set your policy.
Can AI detect candidate fraud? AI runs several of the controls (document analysis, identity verification, and automated verification outreach), but it doesn't replace the layered design. The most useful thing AI changed on the defense side is cost: verification that was too slow and expensive to run on every candidate can now run on all of them.
The Category Is Wider Than Any One Tool
Candidate fraud gets discussed as though it were a single problem with a single product-shaped answer, and it isn't. Five distinct types fail five different screening layers, and the failure most organizations actually experience isn't an exotic deepfake — it's an ordinary-looking candidate whose last two roles were never independently confirmed with anyone who worked there. Fix the sequence, verify the claims that drive the decision, and the exotic cases have far less room to operate.
