Refolk
August 26, 2026·9 min read

38.5% of Interviews Flagged: Inbound Is Now a Fraud Channel

Fabric flagged 38.5% of 19,368 interviews for AI cheating. Here is why inbound became a fraud channel and outbound sourcing is now identity verification.

fake candidates 2026AI candidate frauddeepfake job interviewsverified candidate sourcingoutbound recruiting fraud defense
38.5% of Interviews Flagged: Inbound Is Now a Fraud Channel

If you still think of inbound as your primary top-of-funnel, you are running a fraud channel and calling it recruiting. Fabric's analysis of 19,368 live Round-1 interviews between July 2025 and January 2026 flagged 38.5% of them for AI-cheating behavior, and GoodTime's 2026 Hiring Insights Report - based on a November 2025 survey of 500+ U.S. TA leaders at 1,000+ employee companies - put fraudulent and AI-assisted candidates at the top of anticipated hiring challenges for the year, ahead of talent shortage.

Inbound applications are now an adversarial surface

Open application boards are the cheapest place in tech hiring to attack, so the volume you receive is no longer a proxy for interest. Fraud rings optimize for one-to-many spam, and a single DPRK IT-worker cell documented in the WSJ's August 2026 Infiltrated dossier pushed 1,000+ applications in three months from just 7 identities, with 22 interviews scheduled in a single week.

The mechanism is boring and it is why detection keeps losing:

  • Applying is free. Sourcing costs something.
  • LLM-generated resumes are indistinguishable from good human resumes at the ATS layer.
  • Real-time interview copilots (Cluely, Interview Coder, Final Round AI) mean the person on the Zoom does not need to know the answers.
  • Human reviewers detect deepfake video at 55.54% accuracy, barely better than a coin flip.

Cluely is worth naming specifically. Its founders were suspended from Columbia for using their own product in a technical interview, then raised $5.3M under the tagline "cheat on everything" and hit roughly $3M ARR. Cheating tooling is not fringe anymore. It is a funded, mainstream SaaS category selling into the same buyer you are trying to hire.

38.5%
Round-1 interviews flagged for AI-assisted cheating
Fabric analyzed 19,368 live interviews between July 2025 and January 2026.

The numbers, in one table

Every row is from Fabric's public analysis, GoodTime's report, Checkr, or Refolk's index. None of it is modeled.

SegmentFigureSource
All roles, live interviews flagged (Jul 2025 - Jan 2026)38.5% (7,457 of 19,368)Fabric
Technical roles cheating rate48%Fabric
Sales roles cheating rate12%Fabric
Tech vs. sales exposure4.0xDerived
Flag rate growth, Jul 2025 to Sep 20259% to 45%Fabric
Flagged cheaters who would still pass the interview61.1%Fabric
Broader sample flag rate, Jun 2025 to Dec 202515% to 35%Fabric (50,000+ candidates)
Companies that encountered identity fraud among new hires23%Checkr
TA teams using, piloting, or planning AI agents99.8%GoodTime
U.S. software engineers with verifiable GitHub footprint~12,200Refolk's index

Two rows do most of the work. The 9% to 45% jump in a single three-month window is a 5.0x move, which is not a trend, it is a regime change. And 61.1% of flagged cheaters clearing a 7.0 pass threshold means your current pass/fail signal is anti-correlated with truth for a large minority of candidates.

The interview score is now an anti-signal for tech roles

For technical hires, a clean Round-1 performance from a junior candidate is now a reason to raise your prior on fraud, not lower it. Fabric flagged 48% of technical interviews vs. 12% of sales interviews, and junior candidates (0 to 5 years of experience) cheated at nearly double the rate of seniors.

Think about that Bayesian for a second. If:

  1. The technical base rate for cheating is 48%.
  2. Juniors cheat at roughly 2x the senior rate.
  3. 61% of cheaters clear a 7.0 pass threshold.

Then a smooth, articulate junior backend candidate who nails a live coding round is closer to a coin flip than to a hire. That is not cynicism, that is arithmetic. The old heuristic ("they crushed the screen, advance them") has quietly inverted for one very specific slice of your funnel, and it is the slice you interview the most.

A clean Round-1 from a junior technical candidate is now a reason to raise your fraud prior, not lower it.

Seniors are safer for the boring reason that they have more surface area to check. A decade of commits, three named employers, a conference talk, and a coauthored paper are all expensive to fake individually and nearly impossible to fake coherently.

Outbound is the new identity layer

The cheapest identity verification you own is the decision to source outbound from people with a verifiable public footprint. Fraud rings optimize for reply-to-anything inbound; targeted outreach removes their leverage entirely, because the attacker cannot pretend to be a specific GitHub account that has been committing to a specific repo since 2019.

This is the inversion that matters. For a decade the received wisdom was "let inbound do the work." In 2026 the inbound channel is where the adversary lives, and outbound is the clean room. The signals that are expensive to fake all live outside the interview:

  • Multi-year commit history under a single handle
  • Prior-employer overlap you can triangulate with two references
  • A coherent open-web trail (talks, blog posts, coauthors, PRs merged by named maintainers)
  • Contribution patterns consistent with a working timezone and a working life

None of these are things a DPRK operator or a Cluely-armed junior can spin up in a week. In Refolk's index, roughly 12,200 U.S.-based Software, Backend, and Full-Stack Engineers surface an explicit, verifiable GitHub footprint on their profile. That is the outbound-sourceable "verified human" pool for backend roles, and it is a concrete number to build a pipeline against.

Why "verify before the interview" beats "detect during the interview"

Detection-during-interview is losing an asymmetric arms race. Every new detector prompts a new evasion, and the evasion ships as a product with a landing page. Verification-before-interview does not have this dynamic because the artifacts you are checking (years of commits, employment history, coauthors) were laid down before the attacker knew you existed.

The August 2026 BCA LTD / NorthScan / ANY.RUN sting is the tell. Researchers stood up a fake crypto startup, hired 3 suspected DPRK operatives, and the forensic tell that busted the operation was not a liveness check or a deepfake detector. It was a Google SynthID watermark embedded in a submitted "driver's license." Out-of-band signals caught the fraud. In-band signals did not.

The cost of a bad hire is no longer salary plus rehire

Once a fraudulent candidate is onboarded, you are not looking at a bad-hire cost, you are looking at an insider threat. The DOJ sentenced New Jersey facilitator Kejia "Tony" Wang to 9 years in April 2026 for a scheme that placed DPRK workers at more than 100 U.S. companies using at least 80 stolen identities and earned North Korea $5M+.

The exposure stack now looks like:

  1. Salary paid to a foreign adversary. Recoverable in theory, gone in practice.
  2. Source-code access from Day 1. Real employee credentials on real repos.
  3. Sanctions risk. Skadden and NYSBA both flag OFAC exposure. DOJ has not fined victim companies yet, but "yet" is doing work in that sentence.
  4. Board and audit questions. Explaining to an auditor why your ATS is your identity verification layer is a bad meeting.

Christina Chapman, the Arizona "laptop farm" operator convicted earlier in the DPRK enforcement wave, is a useful shorthand here. The economic model is not shadowy. It is a domestic facilitator, a shipped MacBook, and a login. That is the entire supply chain your inbound funnel is currently subsidizing.

What to actually do in Q4 and Q1

Rebuild the top of your funnel around verified outbound and treat inbound as a low-trust channel that requires additional evidence. Concretely:

  1. Cap inbound as a percentage of interviews. If Fabric's 38.5% flag rate is even directionally right for your stack, every inbound interview slot is a coin flip. Cap it.
  2. Require an out-of-band artifact before Round 1. A GitHub handle with commits older than the job posting, a coauthored paper, a talk video, a named prior manager. Not a portfolio site, which is trivial to fabricate.
  3. Source outbound against the verifiable pool. For U.S. backend, that is roughly a 12,200-person universe with explicit GitHub footprints. Refolk lets you describe the person in plain English (years of commits, prior employers, geography, language stack) and returns the ranked shortlist across GitHub, LinkedIn, and the open web.
  4. Move liveness checks earlier. A five-minute pre-screen video call with the recruiter, not the hiring manager, catches most low-effort deepfakes without burning engineering time.
  5. Log the SynthID/watermark trail. Any AI-generated ID document that passes through your workflow leaves a signature. Retain and audit.
  6. Reframe recruiter metrics. Applications-per-req is now a vanity metric at best and an adversarial one at worst. Verified-candidates-per-req is the number that matters.
5.0x
Growth in AI-cheating flag rate in one quarter
Fabric's flag rate jumped from 9% in July 2025 to 45% by September 2025.

The enterprises GoodTime named in its coverage - Databricks, HubSpot, HelloFresh, Aon - are not doing anything exotic. They are moving budget from inbound processing to outbound sourcing and pre-interview verification. That is the whole play.

FAQ

Is the 38.5% AI-cheating rate representative of all interviews or just AI-conducted ones?

Fabric's 19,368-interview dataset covers Round-1 interviews conducted through its AI interviewer platform between July 2025 and January 2026, so it skews toward companies that already automated first-round screening. That said, the trajectory (9% to 45% in one quarter, and 15% to 35% across a broader 50,000-candidate sample) is consistent enough that treating 38.5% as a directional floor for high-volume technical funnels is defensible. If anything, human-run interviews likely miss more, given the 55.54% deepfake detection accuracy.

Does outbound sourcing actually reduce fraud, or does it just move it?

It reduces it because the attacker's economics collapse. Inbound fraud works because one identity can hit 1,000+ jobs in three months, as the WSJ DPRK dossier showed. Outbound targeting inverts this: the recruiter picks the specific human first, and the fraud ring cannot pretend to be a specific GitHub contributor to Kubernetes with a 2019 commit history and a named prior employer. Fake identities are optimized for volume, not for standing up to a targeted check.

How do I verify a candidate has a real GitHub footprint without wasting recruiter time?

Look for three things: commits older than the job posting under a single handle, at least one merged PR in a repo owned by someone other than the candidate, and a rough match between the commit timezone and the claimed geography. All three are cheap to check and expensive to fake. Refolk surfaces the GitHub footprint on the roughly 12,200 U.S. backend engineers where it exists, so the verification step is one column in your shortlist rather than a separate research pass.

What is the single biggest mistake teams are making right now?

Doubling down on interview-side detection. Every dollar spent on deepfake detectors, keystroke analyzers, and browser lockdowns is a dollar in an arms race against a well-funded product category (Cluely alone is at ~$3M ARR). The same dollar spent on outbound sourcing against verifiable public footprints buys a pool the adversary cannot enter in the first place. Verify before the interview, not during it.

Try it on the search you came here for

Stop building boolean strings. Just describe the person.

Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.

  1. 01Describe them

    One plain sentence. Role, city, stack, stage, whatever matters to you.

  2. 02I read the web live

    GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.

  3. 03You read the shortlist

    Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.

  • No boolean, no filters, no seat to buy. One box.
  • Read at search time, so a profile updated yesterday counts today.
  • Every step visible as it runs, every name with its reason.

500 free credits on sign-up. No card, no demo call. See real searches.

Read next