The Candidate Cleared Every Screen. The Candidate Wasn't Real.
Gartner projects one in four candidate profiles will be fake by 2028. Keyword matching cannot tell a real career from a manufactured one.
In the summer of 2024, a US security-awareness company called KnowBe4 ran a software engineer through its full hiring process. Four video interviews. A resume that checked out. A background check against a real, valid US identity. A photo that matched the person on the calls. They made the offer. The new hire accepted.
The moment the company laptop arrived at the shipping address, it started loading malware.
The "engineer" was a North Korean operative working through a US-based intermediary, using a stolen American identity and an AI-enhanced photo. The company caught it fast and lost nothing. But the part worth sitting with is not that it was caught. It is that the candidate cleared every screen a modern hiring pipeline is built to run. The resume parsed cleanly. The keywords matched. The identity check passed against documents that were technically genuine. Every automated gate in the funnel returned green.
The screening stack did exactly what it was designed to do. It just turned out that what it was designed to do has almost nothing to do with whether the person on the other end is real.
This is the failure mode that the next three years of hiring will be organised around. Not bad hires. Fake ones.
One in four
Gartner put a number on it in a report published in July 2025: by 2028, one in four candidate profiles worldwide will be fake.
That is not a projection about spam applications or exaggerated resumes. It is a projection about profiles that do not correspond to a real, available person doing the work described. In a single survey of 3,000 job candidates, 6% admitted outright to interview fraud — either posing as someone else or having someone else pose as them in an interview. Four in ten said they use AI somewhere in the application process. And in a detail that should unsettle anyone who runs a funnel, only about half of candidates said they even believed the jobs they were applying to were real.
Both sides of the hiring market have quietly stopped assuming the other side is genuine.
"It's getting harder for employers to evaluate candidates' true abilities, and in some cases, their identities," Jamie Kohn, a senior research director in Gartner's HR practice, said when the research landed. "Candidate fraud creates cybersecurity risks that can be far more serious than making a bad hire."
That last sentence is the one most companies have not internalised yet. A bad hire is a productivity problem. A fraudulent hire is a breach.
What hiring managers are already seeing
The 2028 number reads like a forecast. The on-the-ground data reads like it has already arrived.
Checkr surveyed 3,000 American managers in 2025 for a study it called the Hiring Hoax. Nearly one in three — 31% — said they had personally interviewed a candidate who turned out to be using a fake identity. Thirty-five percent confirmed that someone other than the listed applicant had taken part in a virtual interview. Fifty-nine percent said they had suspected a candidate of using AI to misrepresent themselves at some stage of the process.
Greenhouse's 2025 AI-in-hiring research, which surveyed more than 4,100 people across the US, UK, Ireland, and Germany, found the number even higher at the top of the funnel: 91% of US hiring managers said they had encountered or suspected AI-generated answers during online interviews. Sixty-five percent said they had caught applicants using AI deceptively — reading from AI-generated scripts (32%), hiding prompt injections inside resumes to manipulate automated screeners (22%), or showing up as outright deepfakes (18%).
And the part that should end the debate about whether the current screening stack is winning: 62% of hiring professionals said they believe job seekers are now better at faking their identities with AI than HR teams are at detecting the fakes.
When the people running the process tell you, by a near two-thirds majority, that the people they are screening are beating them — the process is not a filter anymore. It is theatre with a pass rate.
This isn't embarrassing. It's a breach.
The reason candidate fraud has graduated from an HR nuisance to a board-level risk is that the most sophisticated version of it is not a job seeker padding a resume. It is organised, state-level infiltration.
In a series of actions through 2024 and 2025, the US Department of Justice indicted North Korean nationals and their facilitators for a scheme that placed fake remote IT workers inside roughly 100 US organisations — including, court documents noted, many Fortune 500 companies. The operation, run through front companies and a network of US-based "laptop farms," funnelled at least $88 million to the North Korean regime over six years. Nike unwittingly paid more than $75,000 to one such worker. In raids across 16 states, the DOJ seized around 200 laptops from farms whose only function was to make a worker in Pyongyang look like they were logging in from Ohio.
The FBI's own framing was that this is "just the tip of the iceberg," with thousands of trained operatives running the same playbook against US companies every day. KnowBe4 — the company from the opening of this piece — later disclosed it had received more than 100 applications from suspected North Korean IT workers in a single year. One slipped through.
Strip away the geopolitics and the mechanic is universal. A hiring funnel is now a way into a company's systems, payroll, and data. Every remote role that gets filled by parsing a resume and running a few video calls is a potential ingress point. The candidate who games the screen does not just take a salary they did not earn. They get a laptop, credentials, and network access — handed over by the company, through the front door, because the screening stack said they were a match.
A vendor that launched deepfake detection for live interviews in early 2026, InCruiter, reported finding fraudulent activity in 25–30% of the sessions it flagged as suspicious — roughly double what experienced human interviewers had been catching on their own. The fraud was always there. The detection just hadn't been.
The resume machine is the vulnerability, not the defence
Here is the uncomfortable structural point, and it is the one most "how to spot a fake candidate" guides skip.
The entire automated screening paradigm — resume parsing, keyword matching, ATS ranking, AI match scores — rests on a single buried assumption: that the document in front of you corresponds to a real person who actually did the things it lists. That assumption was always shaky. Fraud doesn't bend it. It deletes it.
And once you remove that assumption, the machinery doesn't just fail to help. It actively makes the problem worse, for three reasons.
First, a fabricated profile keyword-matches better than a real one. A genuine career is lumpy. It has the wrong title for two years, a gap, a sideways move, a skill that's adjacent rather than exact. A manufactured profile is engineered against the job description — every required keyword present, every must-have satisfied, no awkward edges. The screen that rewards keyword density is, by construction, rewarding the synthetic candidate over the human one. The filter is optimising in exactly the wrong direction.
Second, the resume parser is now an attack surface in the literal security sense. Twenty-two percent of the managers Greenhouse surveyed had caught candidates embedding hidden prompt-injection instructions in their resumes — text designed not for a human reader but to hijack the AI doing the screening into scoring the candidate favourably. When your filter is a language model reading attacker-controlled text, the filter is not evaluating the candidate. The candidate is programming the filter.
Third, AI is screening AI. We have written before about the hiring arms race — AI-written resumes scored by AI screeners, with no human anywhere measuring anything real. Fraud is that arms race weaponised. The same tools that let an honest applicant polish a resume let a fraudster fabricate one wholesale, generate a matching identity, and pipe a deepfake through the video round. The screening stack cannot tell the two apart because it was never measuring the thing that separates them. It was measuring the document.
You cannot keyword-match your way out of a problem that keyword-matching created the opening for.
Why adding more filters makes it worse
The reflex, when the funnel springs a leak, is to add gates. More verification steps. More assessment rounds. Tighter automated checks. It feels like rigour. It mostly relocates the cost onto the wrong people.
Every additional automated gate is a target the fraudster optimises against — they have the time, the tooling, and the incentive to beat a known, repeatable check. The honest candidate, meanwhile, experiences the same gauntlet as friction, distrust, and delay. The data already shows them voting with their feet: only about a quarter of candidates trust AI to evaluate them fairly, only half believe the roles they apply to are even real, and 62% told Gartner they were more likely to apply when a role required an in-person interview — a direct signal that the human, harder-to-fake parts of the process are what genuine people actually want.
So the arms-race response produces a perverse sort: the fraudsters, who treat every gate as a puzzle to solve, push through. The strong real candidates, who treat the same gates as a sign the company doesn't trust them, drop out. You don't tighten the funnel. You change who survives it — toward the people most willing to game it.
The screening team then logs higher fraud-detection rates as evidence the system is working, while the quality of the genuine pool quietly degrades. The metric improves. The outcome gets worse. It's the same trap every other part of automated hiring keeps falling into, wearing a security badge this time.
What actually survives a fraud-saturated market
If the document can't be trusted and more gates make it worse, what's left?
The thing fraud is worst at faking: a coherent, evidence-backed career trajectory that holds up to cross-examination.
A keyword can be invented in a sentence. A degree can be claimed in a line. A photo can be generated in seconds. What is genuinely hard to fabricate is a consistent pattern of work over time that cross-references against reality — the arc of how someone moved between roles, the specific problems they owned and the order they owned them in, the people and outcomes that corroborate the story, the way a real trajectory connects rather than just stacking the right nouns. Manufactured profiles fall apart not at the keyword layer, where they're strongest, but at the trajectory layer, where the pieces have to actually fit together.
That is a different evaluation object entirely. It is not "does this document contain the right terms." It is "does this represent a real person's real path, and does that path predict they can do this job." Answering it requires anchoring on the pattern of a career rather than the contents of a page, treating verification of who someone is as a first-class part of the decision rather than a checkbox at the end, and keeping human judgment in the loop precisely where machines are easiest to fool — the final call on whether a person is who and what they claim to be.
The companies that handle the next three years well will not be the ones with the most screening gates. They will be the ones that stopped trusting the document and started evaluating the trajectory — because a trajectory is the one thing a fake candidate can't assemble out of keywords.
The candidate who clears every screen and isn't real is not a freak event anymore. By 2028, on Gartner's numbers, one in four profiles will be that candidate. The screening stack that can't tell the difference isn't a defence against them. It's the door they walk through.
AgentR evaluates candidates on the pattern of a real career — the trajectory, the evidence, the way the pieces actually fit — rather than the keywords a profile was engineered to contain. In a market where one in four candidates may not be real, the resume is the attack surface, not the signal. If your funnel is screening documents instead of verifying careers, you're measuring the wrong thing. Let's talk.