479 Corporate Victims: Candidate Fraud Is an Inbound Problem
Deepfake hiring fraud jumped 1,300% and 41% of orgs have hired a fake. The fix is not another verification tool. It is outbound sourcing.
ERE published "Nobody Wants to Own Candidate Fraud" on August 19, 2026, and the piece lands on an uncomfortable truth: CISOs won't touch it, TA doesn't have headcount for it, and every vendor pitching a fix assumes the fraudulent candidate at least deserved an interview. They don't. If ~12% of the applications on a real job posting are fake, the cheapest defense is to stop trusting the inbound funnel at all.
The numbers make inbound indefensible
Candidate fraud is no longer a rounding error in the applicant pool; it is a structural feature of it. Three separate DOJ prosecutions of the North Korean IT worker scheme in the last 18 months name 479+ corporate victims combined, and independent detection data says the fake-application rate on ordinary job posts is already in double digits.
Here is the dataset the industry is trying not to look at:
| Metric | Value | Source |
|---|---|---|
| Deepfake fraud attempts, YoY change | +1,300% | Pindrop 2025 VISR |
| Orgs that unknowingly hired a fraudulent candidate | 41% | GetReal Security |
| Fake applications on one Pindrop job post | ~12% (100 of 827) | Fortune, April 2025 |
| DOJ Chapman scheme: US businesses defrauded | 300+ | DOJ |
| DOJ Chapman scheme: revenue to DPRK | $17M+ | DOJ |
| FTC job-fraud losses, 2020 to 2024 | $90M to $501M (+457%) | FTC |
| Companies with formal anti-deepfake protocols | 13% | Wiley / Interview Guys |
| Human accuracy at spotting a deepfake | 55.54% | Wiley |
Pindrop went from roughly one deepfake fraud call per month to about seven per day. Pindrop is a voice-fraud vendor with unusually good telemetry, so its numbers run hot, but the direction is the same everywhere: the FTC's job-fraud loss total climbed from $90M in 2020 to $501M in 2024, a 457% increase in four years. Gartner is now telling clients to assume 1 in 4 candidate profiles worldwide will be fake by 2028, and in its 2Q25 survey of 3,000 job seekers, 6% admitted to interview fraud outright.
Why the North Korea scheme is a leading indicator, not the whole story
The North Korean IT worker scheme is the loudest signal but not the largest population. It is a state-run operation that places DPRK developers into remote Western jobs using stolen or synthetic identities, and the domestic baseline of resume padding, AI-assisted interview cheating, and identity laundering was already there before it scaled.
The DOJ record is now specific enough to plan around:
- Christina Chapman (Arizona), sentenced in 2025 after running a laptop farm with 90+ machines in her home, using 68 stolen American identities to defraud 300+ US businesses and funnel $17M+ to the DPRK.
- June 2025 DOJ sweep: North Korean actors, with facilitators in the US, China, UAE, and Taiwan, obtained employment at 100+ US companies including Fortune 500 firms.
- January 2025 indictment: 64 additional victim companies named.
- KnowBe4, a security-awareness training company, publicly disclosed in summer 2024 that it hired a North Korean IT worker. If KnowBe4 got hit, the "we would notice" defense is dead.
One founder told Fortune that ~95% of the resumes he receives are from North Korean engineers pretending to be Americans. That is an outlier, but Palo Alto Networks has demonstrated that someone with zero image-manipulation experience needs about 70 minutes to build a deepfake candidate capable of passing a video interview. The tooling is commoditized. The economics favor the attacker.
Strip out the DPRK entirely and the funnel is still compromised. Gartner's 2Q25 survey put self-admitted interview fraud at 6% of job seekers, and the forecast is 1 in 4 fake profiles worldwide by 2028. This is not a geopolitics story. It is a funnel-integrity story.
The verification-tool market is fighting the last war
Buying a deepfake detector to bolt onto the interview stage assumes the fake candidate deserved an interview. The math says they didn't, and the layered-defense pitch is quietly an admission that no single vendor works.
Kevin Lagunas, quoted in the ERE piece, put it plainly: "no single tool stops candidate fraud." The emerging best practice is a stack of top-of-funnel filters, deeper identity verification, and human diligence. Only 13% of companies have formal anti-deepfake protocols today, and humans catch deepfakes at 55.54% accuracy, barely above a coin flip. Google, Cisco, and McKinsey have already reintroduced mandatory in-person interviews for at least some roles, per WSJ reporting from mid-2025. That is not a scalable answer for a Series B with three offices and remote reqs.
The ownership vacuum ERE identifies is really a budget vacuum. If CISOs won't own candidate fraud and TA doesn't have the headcount, budget will not flow to inbound-cleanup software at enterprise scale. It will flow to whoever can promise fewer, higher-signal candidates. That is a structural tailwind for outbound sourcing and referrals, not for another AI screening layer.
A 70-minute deepfake is trivial. A five-year commit graph tied to a verifiable email is not.
Outbound sourcing is structurally fraud-resistant
Outbound sourcing beats fraud not because sourcers are smarter, but because the artifacts a sourcer starts from cannot be fabricated retroactively. You are not evaluating a resume submitted today. You are evaluating a professional footprint that had to exist yesterday.
The artifacts that resist state-actor forgery:
- A GitHub account with 5+ years of commit history tied to a verifiable email domain, with pull requests reviewed by named humans at named companies.
- A LinkedIn profile with multi-year tenure and mutual connections at each listed employer, not a two-month-old profile with 47 connections.
- Conference talks on YouTube with the candidate's face, voice, and slide deck under their name, indexed by third parties.
- Coauthored papers, patents, or Stack Overflow reputation with citation trails that predate the current hiring cycle.
- A personal domain registered years ago with matching WHOIS history.
A deepfake candidate can pass a 45-minute Zoom. A deepfake candidate cannot retroactively author a merged pull request in a widely-used open source repo in 2019. This is why "verify candidate identity" is a losing framing at the interview stage and a winning framing at the sourcing stage. You are not verifying an identity a candidate presented to you. You are starting from an identity the internet already witnessed for years.
This is the exact gap Refolk closes for teams that want to shift budget from inbound cleanup to outbound coverage: you describe the person you actually want in plain English (say, "senior backend engineer with 4+ years of commits to a distributed database, US-based, ex-fintech") and get back a ranked shortlist built from GitHub, LinkedIn, and the open web, where every profile has an evidentiary trail longer than any deepfake pipeline can fake.
The sourcer supply problem is the real bottleneck
If every mid-market company shifted 30% of reqs from inbound to outbound tomorrow, the US labor market could not staff it. There are not enough sourcers, and that is the wedge.
In Refolk's index of professional profiles, only ~1,737 people in the US carry a Sourcer, Technical Sourcer, or Talent Sourcer title. That is the entire defensive line if you accept outbound as the fix. Pindrop alone logs the equivalent of seven deepfake incidents per day; extrapolate that across the US remote-hiring market and 1,737 humans cannot manually run the outbound motion needed to replace the compromised inbound funnel.
Two things follow from that number:
- The market cannot hire its way out. You are not going to double the sourcer population in a year. The 41% of companies who already onboarded a fake do not have a sourcing team ready to absorb the shift.
- AI-native sourcing tooling is not optional. The only path where a mid-market recruiter runs an outbound-heavy pipeline is one where one recruiter does the work of five. Refolk exists for exactly this shape of problem: plain-English requests, verified profile trails, no boolean gymnastics.
What to actually do this quarter
Treat candidate fraud as a funnel-mix problem, not a detection problem. Shift the ratio of inbound to outbound for any role where a compromised hire is a security incident, and layer verification only on the smaller inbound residue that remains.
A concrete 90-day plan:
- Segment reqs by blast radius. Any role with production access, customer data, or code-signing keys moves to outbound-first. Marketing coordinator can stay inbound.
- Set an outbound floor per segment. For sensitive roles, target 70%+ of interviews from sourced candidates with 3+ year public identity trails. Measure it weekly.
- Encode identity floors in your sourcing brief. "5+ years of GitHub activity," "2+ years current LinkedIn tenure," "verifiable prior employer with mutual connections." A tool like Refolk lets you say this in plain English instead of stapling it into a boolean string.
- Keep inbound, shrink its trust. Assume Gartner's guidance that 1 in 4 profiles will be fake by 2028 is already directionally true. Route every inbound to a lightweight identity check before any human time is spent.
- Pick one anti-deepfake control for the interview stage. Live coding on shared screen with camera on, government ID cross-checked against LinkedIn photo, or an in-person final round for the top two. One control, enforced, beats three unenforced ones.
- Give RecOps the budget line. Lagunas predicts this lands with RecOps. Fund it there or the ownership vacuum stays open.
The teams that will look smart in 12 months are the ones who read the 1,300% number, the 479 corporate victims, and the 41% "already hired a fake" figure and concluded that the inbound funnel is the vulnerability, not the interview. Everyone else will be shopping for their second deepfake detector.
FAQ
Is candidate fraud a hiring problem or a security problem?
Both, which is why it keeps falling through the cracks. ERE's August 2026 piece documents CISOs declining to own it because it starts before onboarding, and TA declining to own it because it looks like a security threat. In practice it is a funnel-integrity problem sitting with RecOps: the fraud enters through the applicant tracking system, but the damage lands in production. Fund it out of the hiring budget, staff it with sourcers and RecOps, and give the CISO veto power on controls for sensitive roles.
Won't better deepfake detection eventually solve this at the interview stage?
Unlikely on the timeline that matters. Palo Alto Networks showed a novice can build a passable deepfake candidate in 70 minutes, humans catch them at 55.54% accuracy, and only 13% of companies have formal anti-deepfake protocols. Detection is a cat-and-mouse game where the mouse gets cheaper every quarter. Outbound sourcing against multi-year public identity trails is a different game entirely: you are evaluating history that already happened, not a stream a model is generating live.
How is outbound sourcing actually harder to fake than inbound?
Because the artifacts predate the hire. An inbound applicant hands you a resume and a Zoom presence, both authored this week. An outbound target is someone whose GitHub commits, LinkedIn tenure, coauthored papers, and conference talks were witnessed by third parties over years. A state actor can fabricate a persona for a 45-minute interview. They cannot retroactively insert five years of merged pull requests into public repos with named reviewers at named companies.
Where does Refolk fit in a layered defense?
Refolk sits at the top of the outbound funnel: you describe the person in plain English, including identity floors like years of public activity or tenure at named employers, and get back a ranked shortlist across GitHub, LinkedIn, and the open web. It does not replace interview-stage verification for the inbound residue you still take, but it changes the mix so that residue is small enough to verify properly. The goal is fewer, higher-signal candidates, sourced from identities the internet already witnessed.
Try it on the search you came here for
Stop building boolean strings. Just describe the person.
Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.
01Describe them
One plain sentence. Role, city, stack, stage, whatever matters to you.
02I read the web live
GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.
03You read the shortlist
Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
- No boolean, no filters, no seat to buy. One box.
- Read at search time, so a profile updated yesterday counts today.
- Every step visible as it runs, every name with its reason.
500 free credits on sign-up. No card, no demo call. See real searches.