Gartner's 1-in-4 Fake Candidate Stat: Filter at Sourcing, Not Interview
Gartner projects 25% of candidates will be fake by 2028. Three cross-platform proof-of-work filters kill synthetic profiles at sourcing, before interviews.
If a quarter of your inbound engineering funnel is synthetic, the "hold your hand in front of your face" trick every recruiter is now sharing on Slack fires five hours too late. That's five hours per fake, on a req that Gartner projects will be 25% fake by 2028.
Gartner's July 31, 2025 report is the number driving the panic, and the response so far has been interview-stage detection: liveness checks, gesture tests, deepfake artifact spotting. The Vidoc Security demo that put "wave your hand" into every recruiter's feed is real, and the DPRK laptop-farm case that sent Christina Chapman to prison for 8.5 years is real. Both cost the employer time and reputation because the fraud was caught at interview or later, not at the top of the funnel. Sourcing filters built on cross-platform proof-of-work catch the same profiles earlier, cheaper, and without the awkward video moment.
Why interview-stage detection is the wrong battlefield
Interview-stage checks catch fakes after you've already paid for them. Vidoc Security's co-founder Dawid Moczadlo went viral on LinkedIn for asking an AI-generated candidate to hold a hand in front of their face, a gesture that disrupts current deepfake filters, and ending the call when the candidate refused. Vidoc's postmortem said the team lost more than five hours on that single candidate before the ask. Multiply that by a 25% synthetic rate on a 200-applicant req and the math is brutal.
The deeper problem is structural. Filters that only fire on video assume:
- The recruiter has already screened, scored, and shortlisted the profile.
- A hiring manager has cleared calendar time.
- A coordinator has scheduled a Zoom.
- The candidate has opted into a live channel where deepfake artifacts are detectable.
Every one of those steps costs money. And the FBI's Elizabeth Pelker has been explicit that DPRK remote workers specifically target software engineer, front-end developer, and full-stack developer jobs, which is the exact funnel every technical recruiter runs. This is not a SecOps problem to punt to IT. It's a sourcing-workflow problem.
The three signals generative models cannot fabricate
Three cross-platform proof-of-work signals separate real engineers from synthetic ones at sourcing: a backdated GitHub graph tied to the claimed identity, timezone-consistent contribution patterns, and a long-tail community footprint (conference talks, mailing lists, issue conversations). Fake candidates fail on at least one, and usually all three.
The mechanism matters. A generative model can produce a plausible LinkedIn headline, a plausible resume PDF, and a plausible README on a freshly created GitHub account. It cannot produce years of commits merged into other people's repositories, code review conversations with named maintainers, and CFP acceptances at conferences that publish speaker lists. These signals are backdated, cross-referenced, and socially anchored. Fabricating them retroactively would require compromising the accounts of the maintainers who reviewed the PRs, which is a nation-state-tier attack, not a laptop-farm operation.
Signal 1: a real, backdated GitHub tied to the claimed name
Ask for a GitHub URL on the application form. Then check that the account has commits older than the claimed first job, PRs merged into repos the candidate does not own, and a profile name or bio that ties to the LinkedIn identity. In Refolk's index, a search for US-based Software, Backend, and Full-Stack Engineers with GitHub credentials visible on their public profile returned 12,378 people. That's a small number relative to total US engineering headcount, and that's the point: requiring a real, populated GitHub is itself a strong filter, because most fake profiles do not have a backdated GitHub tied to their claimed identity.
Signal 2: timezone-consistent commit history
The DOJ raided 29 laptop farms across 16 states in late June 2025 and seized around 200 laptops. Those farms exist because DPRK operatives present as US-based but the human on the keyboard is not. Commit timestamps expose this immediately. A candidate claiming Austin, Texas, whose GitHub graph shows dense activity between 2 a.m. and 10 a.m. Central for three years, is not in Austin. Timezone consistency is not a heuristic that requires AI. It requires reading the graph.
Signal 3: long-tail community footprint
A real senior engineer leaves footprints outside LinkedIn: Stack Overflow answers, conference talks with recorded video, mailing list posts, HN comments tied to a consistent handle. In Refolk's index, only 7 profiles in the sampled slice self-describe as "open source maintainer" or "contributor" for SWE/Backend roles. That's under 0.1%. When a candidate has that signal and it verifies, it's an extraordinarily strong positive. When they claim it and it does not verify, it's an extraordinarily strong negative.
What the numbers actually say
Here is the dataset behind the argument, pulled from Gartner, industry panels, and Refolk's index. Every row is a filter target or a filter output.
| Signal / cohort | Count | Source | What it means for sourcing |
|---|---|---|---|
| Candidate profiles projected fake by 2028 | 25% | Gartner (Jul 31, 2025) | Baseline funnel contamination rate |
| Candidates admitting interview fraud in 2025 | 6% of 3,000 | Gartner survey | Current admitted rate, floor not ceiling |
| Enterprises that have already hired a fraudulent candidate | 41% | BrightHire / Zoom panel | Downstream cost when no pipeline filter exists |
| Orgs that have updated screening for AI fraud | 22% | Mokka | Screening-debt gap of 1.86x |
| HR workers reporting a 2025 surge in AI-generated applications | 9 in 10 | Staffing Hub | Inbound volume is the pressure |
| US hiring managers who've encountered deepfakes in video interviews | ~17% | Adaptive Security (March survey) | Interview-stage cost is already here |
| US SWE / Backend / Full-Stack profiles with GitHub visible | 12,378 | Refolk's index | Usable pool when GitHub is required |
| Profiles self-describing as OSS maintainer / contributor | 7 (sampled slice) | Refolk's index | Under 0.1% rarity, strongest positive signal |
The 1.86x screening-debt gap (41% exposed, 22% updated) is the number your CFO should see. It's the difference between the fraud rate your peers are absorbing and the response rate your peers have actually shipped.
A generative model can fabricate a LinkedIn. It cannot fabricate years of merged PRs tied to a real handle.
Building the three filters into your pipeline
The filters only work if they run before the recruiter opens the profile. That means encoding them as sourcing queries and inbound-scoring rules, not as manual checks a coordinator remembers to do on Fridays.
Here's the sequence I'd run for a US backend req today:
- Require a GitHub URL at application. Not optional. This alone shrinks the fake pool because most synthetic profiles skip it or paste a URL to an account created in the last 90 days.
- Score the GitHub graph on three axes: age of oldest commit, count of PRs merged into repos the candidate does not own, and timezone distribution of commits versus claimed location.
- Cross-reference the LinkedIn name against the GitHub bio, commit author name, and any conference speaker pages or Stack Overflow profile. Names should tie. Fakes usually don't.
- Boost the score for long-tail community footprint: CFP talks, mailing list activity, package maintainership on npm, PyPI, or crates.io.
- Only then look at the resume.
This is exactly the gap Refolk closes for technical sourcing: you describe the engineer you want in plain English and Refolk returns a ranked shortlist that already respects those cross-platform proof-of-work signals. The synthetic profiles never make the list, because the signals they lack are the signals the query requires.
Where the filters break, and how to handle it
No filter is free. Two failure modes to plan for:
- The junior engineer with a thin GitHub. New grads and career-switchers have real identities and thin public footprints. Don't reject on GitHub alone at the junior band. Use it as a positive scoring signal, not a hard gate.
- The privacy-conscious senior. Some legitimate senior engineers keep GitHub private or contribute under a pseudonym. Rare, but real. Give recruiters an override path that requires a second verification (referral from a named ex-colleague, verifiable conference talk, published patent) before the profile advances.
The point isn't a zero-false-positive filter. The point is that the 25% fake rate is heavily concentrated in the segment that also lacks proof-of-work. Filter on proof-of-work and the fake rate in the surviving pool drops sharply, without a proportional drop in real candidates.
Don't confuse AI polish with AI fabrication
Do not conflate AI-polished resumes with AI-fabricated identities. Gartner's data shows 4 in 10 candidates use AI during the application process to write resumes, cover letters, and assessment answers. That's cosmetic enhancement. It's not fraud. It inflates false positives if you filter on "sounds like ChatGPT wrote it," and it burns filter budget on real candidates who used a writing assistant the same way they'd use Grammarly.
The 25% Gartner figure covers a spectrum:
- Cosmetic AI polish. Real person, AI-written prose. Not a fraud problem, a signal-quality problem.
- Credential inflation. Real person, exaggerated or falsified experience. Old problem, not new.
- Full identity fabrication. Fake person, real or stolen photo, generated work history. This is the target.
- Coordinated infiltration. DPRK-style operations where multiple fakes share infrastructure. Microsoft's Jasper Sleet threat intel post from June 30, 2025 is the primary source, documenting how between 2020 and 2022 over 300 US companies including several Fortune 500 firms unknowingly employed DPRK workers.
Proof-of-work filters target categories 3 and 4, which is where the actual damage lives. They intentionally do not target category 1, because targeting category 1 is where recruiters torch real candidates for using Grammarly.
What to ship this quarter
Three concrete changes, in priority order, that a technical sourcing team can ship before end of quarter:
- Make GitHub URL a required field on your application form for engineering roles, and reject applications without it or with an account younger than 12 months. Expect a meaningful drop in applied volume. That drop is mostly the fakes.
- Add a timezone-consistency check to your ATS scoring rubric. If commit timestamps don't match claimed location, flag for manual review, don't auto-reject.
- Score inbound on community footprint (CFP talks, package maintainership, Stack Overflow reputation) and route the high scorers straight to hiring manager review, skipping the recruiter screen entirely. The 7-profiles-in-a-slice OSS-maintainer rarity in Refolk's index tells you these candidates are worth the fast lane.
None of this requires a new video-interview vendor. None of it requires a liveness check. It requires treating sourcing as the first line of defense against synthetic candidates, which is where the 1.86x screening-debt gap actually closes.
FAQ
How do I filter fake candidates at sourcing without rejecting real juniors?
Use GitHub and proof-of-work as scoring signals, not hard gates, at the junior band. Require them as hard gates only at senior and above, where a multi-year public footprint should exist if the claimed experience is real. Juniors get evaluated on take-home performance and referral quality instead. The 25% Gartner fake rate is concentrated in profiles claiming mid and senior experience, because that's where DPRK and AI-fabricated identities target the highest salaries.
Isn't requiring GitHub biased against engineers who work at companies that don't allow open source?
Somewhat, but less than sourcers assume. Even engineers at closed-source shops usually have pre-employment GitHub activity from school, side projects, or prior jobs. Refolk's index of 12,378 US SWE profiles with visible GitHub credentials is a floor, not a ceiling, because it counts only profiles that surface the credential publicly. For the small legitimate cohort with truly no public code, offer an override path (patent, published talk, referenceable open source under a pseudonym you can verify).
Can generative AI eventually fabricate a multi-year GitHub history?
Not in a way that survives cross-referencing. Fabricating commits on a fresh account is trivial. Fabricating merged PRs into repos you don't own requires the maintainer of that repo to have merged them, which happened in real time, in the past, and is recorded in a place the fabricator cannot rewrite. The social graph of code review is the moat, not the code itself.
What's the fastest way to test these filters on my current pipeline?
Take last quarter's applied candidates for one engineering req and re-score them on the three signals: GitHub age, timezone consistency, and community footprint. Compare the top-scored cohort to who you actually advanced. If your advanced pool overlaps heavily with the top-scored cohort, your recruiters are already doing this manually and inconsistently. If it doesn't overlap, you have a screening-debt problem, and the filters will pay for themselves inside one hiring cycle.
Try it on your own search
Stop building boolean strings. Just describe the person.
Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.
- One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
- Read live at search time, not from a database that went stale last quarter.
- Watch every step as it runs, and see why each name made the list.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
500 free credits on sign-up. No card, no demo call. See real searches.