Back to blog

AI-Generated Fake Candidates

JA
Jean-Baptiste Artignan
CEO
November 13, 20254 min read
AI-Generated Fake Candidates

The new silent threat targeting recruitment processes

Recruitment has also become an attack surface. For several months, recruiters and HR teams have reported a worrying rise in fake candidates created using generative AI: synthetic profiles, video deepfakes during interviews, cloned artificial voices...

This threat is still largely unknown to the general public, yet it can expose an organization to major operational and cybersecurity risks.


When AI enters interviews... to deceive recruiters

Thanks to new content-generation tools, it is now possible to create in just a few minutes:

  • a fully AI-generated résumé,
  • a deepfake face capable of smiling, blinking, and reacting in real time,
  • a synthetic voice cloned from five seconds of audio,
  • smooth, polished behavior that is... sometimes too perfect.

As a result, a recruiter may find themselves interviewing a digital avatar without realizing it. Facial deepfakes conceal the interviewee's real identity, while voice deepfakes make their speech sound credible and natural.

Several international investigations have already uncovered cases in which these fake profiles secured remote technical roles, sometimes to infiltrate organizations.


Facial and voice deepfakes: a formidable combination

Deepfakes are no longer spectacular gimmicks reserved for films or high-profile scams.

They have become advanced social-engineering tools.

🎭 Facial deepfake

  • A face generated or altered in real time.
  • Expressions synchronized with the voice.
  • The ability to imitate an existing LinkedIn profile to gain credibility.

🎙️ Voice deepfake

  • A voice cloned in just a few seconds.
  • Accurate reproduction of tone, pauses, and timbre.
  • Difficult to distinguish from a real voice during a simple call.

By combining both, an attacker can present themselves as a convincing candidate, perfectly aligned with the job description... while their sole objective is to deceive the organization.


Why do these fake candidates pose a major cyber risk?

This threat goes far beyond a simple HR issue. It directly affects the security of the organization.

Here are the main risks:

Access to internal systems

A fraudulent candidate hired for a remote role gains:

  • a company laptop,
  • VPN access,
  • access to internal tools,
  • sometimes administrative privileges.

Once inside, they can:

➡️ exfiltrate data

➡️ install malware

➡️ spy on internal communications

➡️ compromise the organization's credentials

Sensitive information leaks

HR teams are already targeted by phishing attacks. Fake candidates add another layer:

  • gathering information about internal processes,
  • obtaining confidential documents (technical information, procedures, diagrams).

Manipulation of the recruitment process

A wave of fake candidates can overwhelm recruitment pipelines, delay projects, and divert HR resources.


How can you protect your organization?

Organizations must strengthen their vigilance and adapt their recruitment practices. Here are the essential measures:

✔ 1. Conduct multiple live interviews

Mandatory camera use, spontaneous interactions, and several stages.

Deepfakes are more vulnerable when exchanges become unpredictable.

Prioritize in-person interviews.

✔ 2. Test skills in real-world conditions

Examples:

  • share a screen,
  • solve a technical exercise live,
  • explain their reasoning.

AI systems struggle to improvise in unscripted contexts.

✔ 3. Verify identity using enhanced methods

  • Request an official document through a secure process.
  • Perform identity verification outside of videoconferencing.
  • Use biometric tools where necessary.

✔ 4. Rely on trusted networks

Referrals and qualified sourcing significantly reduce risks.

✔ 5. Train HR teams and managers

Deepfakes are all the more dangerous because they remain poorly understood.

Awareness is the first line of defense.


Recruitment: a new frontier in cybersecurity

The rise of AI-generated fake candidates marks a major shift:

recruitment is no longer just an HR process, but also an organizational security challenge.

Deepfakes make detection difficult, but not impossible.

With robust processes, a hybrid approach (technology + human vigilance), and continuous awareness, organizations can protect themselves against this emerging threat.

BlueSecure supports its clients on these issues through educational content, awareness tools, and tailored training programs (escape games, scenario-based exercises, live deepfake demonstrations...)

If you would like to learn more, please do not hesitate to contact us.

Discover an all-in-one application

BlueSecure strengthens your teams against cyber threats. Discover everything we can do for you.

By

JA

Jean-Baptiste Artignan

CEO

Share this article