The new silent threat targeting recruitment processes
Recruitment has also become an attack surface. For several months, recruiters and HR teams have reported a worrying rise in fake candidates created using generative AI: synthetic profiles, video deepfakes during interviews, cloned artificial voices...
This threat is still largely unknown to the general public, yet it can expose an organization to major operational and cybersecurity risks.
When AI enters interviews... to deceive recruiters
Thanks to new content-generation tools, it is now possible to create in just a few minutes:
- a fully AI-generated résumé,
- a deepfake face capable of smiling, blinking, and reacting in real time,
- a synthetic voice cloned from five seconds of audio,
- smooth, polished behavior that is... sometimes too perfect.
As a result, a recruiter may find themselves interviewing a digital avatar without realizing it. Facial deepfakes conceal the interviewee's real identity, while voice deepfakes make their speech sound credible and natural.
Several international investigations have already uncovered cases in which these fake profiles secured remote technical roles, sometimes to infiltrate organizations.
Facial and voice deepfakes: a formidable combination
Deepfakes are no longer spectacular gimmicks reserved for films or high-profile scams.
They have become advanced social-engineering tools.
🎭 Facial deepfake
- A face generated or altered in real time.
- Expressions synchronized with the voice.
- The ability to imitate an existing LinkedIn profile to gain credibility.
🎙️ Voice deepfake
- A voice cloned in just a few seconds.
- Accurate reproduction of tone, pauses, and timbre.
- Difficult to distinguish from a real voice during a simple call.
By combining both, an attacker can present themselves as a convincing candidate, perfectly aligned with the job description... while their sole objective is to deceive the organization.
Why do these fake candidates pose a major cyber risk?
This threat goes far beyond a simple HR issue. It directly affects the security of the organization.
Here are the main risks:
Access to internal systems
A fraudulent candidate hired for a remote role gains:
- a company laptop,
- VPN access,
- access to internal tools,
- sometimes administrative privileges.
Once inside, they can:
➡️ exfiltrate data
➡️ install malware
➡️ spy on internal communications
➡️ compromise the organization's credentials
Sensitive information leaks
HR teams are already targeted by phishing attacks. Fake candidates add another layer:
- gathering information about internal processes,
- obtaining confidential documents (technical information, procedures, diagrams).
Manipulation of the recruitment process
A wave of fake candidates can overwhelm recruitment pipelines, delay projects, and divert HR resources.
How can you protect your organization?
Organizations must strengthen their vigilance and adapt their recruitment practices. Here are the essential measures:
✔ 1. Conduct multiple live interviews
Mandatory camera use, spontaneous interactions, and several stages.
Deepfakes are more vulnerable when exchanges become unpredictable.
Prioritize in-person interviews.
✔ 2. Test skills in real-world conditions
Examples:
- share a screen,
- solve a technical exercise live,
- explain their reasoning.
AI systems struggle to improvise in unscripted contexts.
✔ 3. Verify identity using enhanced methods
- Request an official document through a secure process.
- Perform identity verification outside of videoconferencing.
- Use biometric tools where necessary.
✔ 4. Rely on trusted networks
Referrals and qualified sourcing significantly reduce risks.
✔ 5. Train HR teams and managers
Deepfakes are all the more dangerous because they remain poorly understood.
Awareness is the first line of defense.
Recruitment: a new frontier in cybersecurity
The rise of AI-generated fake candidates marks a major shift:
recruitment is no longer just an HR process, but also an organizational security challenge.
Deepfakes make detection difficult, but not impossible.
With robust processes, a hybrid approach (technology + human vigilance), and continuous awareness, organizations can protect themselves against this emerging threat.
BlueSecure supports its clients on these issues through educational content, awareness tools, and tailored training programs (escape games, scenario-based exercises, live deepfake demonstrations...)
If you would like to learn more, please do not hesitate to contact us.



