- "Fake candidate" covers four different things: an embellished CV, an AI-written CV, a borrowed identity and a stolen identity. The first is a hiring problem. The last two are a security problem.
- The scale is not a niche: Gartner expects 1 in 4 candidate profiles to be fake by 2028, and 91% of hiring professionals in Greenhouse's 2025 survey say they have caught or suspected fraud.
- No single signal proves anything. A cluster of signals across independent areas (file, contact data, timeline, identity) is what turns a note into a conversation.
I hired a fake candidate after sixteen years in IT recruitment. That sentence is how I open my talks now, because it gets the room to stop nodding and start listening. If it happened to a team that reviews thousands of CVs a year, it can happen to anyone.
This post is the first of three. It answers the basic question people ask me after every talk: what exactly is a fake candidate? The second post covers who is behind them. The third covers why the problem exploded now and what to do about it from Monday.
A definition that actually helps
A fake candidate is an application where the person, the identity or the story behind it is not what it claims to be.
That is deliberately broad, because the term gets used for very different situations. Here is the spectrum we see in real pipelines.

1. The embellished CV. A real person. Dates stretched by a few months, a “team lead” title that was really “senior”, a technology listed because they sat next to someone who used it. Dishonest, but the person is real, accountable and often a decent hire. Not what this series is about.
2. The AI-written CV. Still a real person. The CV was generated from the job ad, so it matches keyword by keyword. On the call, the candidate pauses four to six seconds before every answer and their eyes drift to a second screen. The skills on paper and the skills in the room are two different people. This is the most common case we see.
3. The borrowed identity. A real worker using someone else’s documents, or a “frontman” who does the interview while someone else does the job. Often three to five full-time jobs at once. The goal is salary. You are paying for a person who is not there.
4. The stolen identity. An operator behind a persona. The name, the photo, the diploma and sometimes the LinkedIn profile belong to someone else, or to nobody. The goal is not the salary. It is access: to code, to customer data, to the VPN. This is the version the FBI and the US Department of Justice have been warning about since 2022, and it is the one that turned into criminal cases with names, laptop farms and sentences.
Categories 3 and 4 are the reason recruitment now has a security dimension. A hired fake worker sits inside your perimeter with real credentials. As Google’s threat intelligence team put it, that is the ultimate insider threat.
How big is it?
The numbers are easy to nod at and hard to feel. What made it real for us was our own pipeline. When we went back through 33 applications our recruiters had flagged in 2025 and early 2026, the same handful of signals kept coming up: no phone number or a VoIP one, a LinkedIn profile created a few weeks before the application with two connections, a PDF whose author metadata was a completely different name, three candidates for one role sharing a phone number block.
One of those, a “senior engineer” with Bolt, Microsoft and UBS on the CV, had a LinkedIn profile from September 2025 with two contacts and a PDF authored by someone else in a tool nobody in Poland uses. Another had nine portfolio links, all dead, a landline phone number and file metadata pointing at Singapore, California and Portugal while claiming to live in Warsaw.
One CV is nothing. Three CVs from the same pool are a farm.
From our CyberHR talk, Łódź 2026
Why one signal is never enough
Here is the mistake I see most often once a team becomes aware of the problem: they start rejecting on single signals. VoIP number, out. Fresh LinkedIn, out. Gap in the timeline, out.
That is wrong twice. It is wrong because honest people have messy CVs. Someone who moved countries has a VoIP number. Someone who was on parental leave has a gap. Someone who just got serious about their job search made a LinkedIn profile last month. And it is wrong because the fabricated applications are increasingly built to pass single-signal checks. They look good on the positives. They have a phone number, a profile, a photo.
What separates a fabricated application from a messy real one is a cluster: independent signals in different areas that all point the same way. Hidden white text in the file, plus a VoIP number, plus two full-time jobs overlapping for 14 months, plus a document edited in a time zone eight hours from where the candidate says they live. No single one of those is damning. Together they are a pattern, and a pattern is worth a verification step before you book the interview.

This is also why we built TalentShield to show signals, never verdicts. The tool tells you what it found, why it matters and how to check it yourself. Whether the candidate is who they say they are is a call a person makes, with evidence in front of them. That is not only fairer to candidates. Under the EU AI Act, tools used to evaluate job applicants are high-risk systems, and human oversight with explainable output is exactly what the regulation asks for.
What this means for you
This is also why the category is called candidate fraud detection rather than fake candidate detection: the fabricated identity is the rare case, the real applicant gaming the screening is the common one.
If you hire remotely, across borders, or for roles with access to code, money or customer data, assume fake candidates are already in your pipeline. Not as a scare, as a baseline.
The good news is that the first layer of defence costs nothing: a one-page list of yellow and red signals for your team, a habit of checking the CV against the public profile, and an alert first screening call. The second post in this series looks at who is on the other side, which makes the signals much easier to understand. The third gives you a plan for Monday.
And if you want to see what automated checks find on your own applicants, inside the ATS you already use, book a demo. Real signals on real candidates, and a weekly call with people who still recruit every day.
Questions people ask
What is a fake candidate?
A fake candidate is an application where the person, the identity or the story behind it is not what it claims to be. It ranges from a real person with an AI-written CV who reads answers off a second screen, through real workers using borrowed documents to hold several jobs at once, to operators using a stolen identity to get inside a company.
How common are fake candidates?
Gartner expects one in four candidate profiles worldwide to be fake by 2028. In Greenhouse's 2025 AI in Hiring report, 91% of the 4,136 hiring professionals surveyed said they had caught or suspected candidate fraud. In our own agency we see signals in a meaningful share of applications for remote tech roles.
Is a fake candidate the same as a lying candidate?
No. Stretching a job title or rounding up a date is dishonest but the person is real and accountable. A fake candidate is one where the identity itself, or the person who will do the work, is not the one you are talking to. The risk is different: insider access, payroll fraud, data theft.
Can one red flag prove a candidate is fake?
No. A single signal is a reason to ask a question. Honest people have VoIP numbers, odd file names and messy timelines. What separates a fabricated application is a cluster of independent signals across different areas, and even then the right response is a human checking the evidence.
Sources
- Gartner, 2025: by 2028, 1 in 4 candidate profiles worldwide will be fake
- Greenhouse, 2025 AI in Hiring Report (n=4,136)
- US Department of Justice, U.S. v. Chapman (2025): Arizona laptop farm, 300+ companies, $17M
- KnowBe4, July 2024: how a North Korean IT worker got hired
- FTC, 2025: job and employment scam losses grew from $90M in 2020 to $501M in 2024
- Team Up / TalentShield, analysis of 33 flagged applications (2026) · internal
