Refolk
August 18, 2026·9 min read

41% Have Already Hired a Fake. Outbound Is Now Fraud Defense.

Fake candidates are the top hiring risk of 2026. Why outbound sourcing is now structurally safer than inbound, with numbers from Gartner, Checkr, and the FBI.

fake candidate hiringnorth korean IT worker frauddeepfake interview detectionoutbound sourcing fraud defenseAI-generated resume fraud
41% Have Already Hired a Fake. Outbound Is Now Fraud Defense.

If your pipeline starts with a self-submitted application in 2026, you are the mark. Nation-state operators, GPU-overlay cheating tools, and AI-generated identities are entering inbound funnels at industrial scale, and the numbers say most companies have already lost.

Gartner's July 31 projection puts 1 in 4 candidate profiles worldwide as fake by 2028. GetReal Security's 2025 survey says 41% of IT, cybersecurity, risk, and fraud leaders have already onboarded a fraudulent candidate. Checkr's 2025 Hiring Hoax survey of 3,000 managers found 23% reporting losses over $50,000 in the past year from hiring or identity fraud. The inbound funnel is no longer just noisy. It is adversarial.

The inbound funnel is now a negative-value channel

For security-sensitive technical roles, the expected fraud cost per inbound applicant now likely exceeds the marginal cost of sourcing an outbound candidate. That reframes outbound from a nice-to-have to the cheaper, risk-adjusted default.

Look at what enterprises are actually paying to keep the inbound door open:

  • 41% of IT, security, risk, and fraud leaders confirm their company has hired a fraudulent candidate (GetReal Security, 2025).
  • 23% of managers report losses over $50,000 in the past year from hiring or identity fraud; 10% report losses over $100,000 (Checkr Hiring Hoax, n=3,000).
  • 60% of managers say they have uncovered a candidate who misrepresented experience.
  • Only 19% of managers are extremely confident their process would catch a fraudulent applicant.
  • 88% of organizations encounter deepfake or impersonation attacks at least occasionally; 45% call them frequent.

The economics are not subtle. In the Kejia Wang case, an overseas co-conspirator used a California defense contractor's laptop to access ITAR-controlled files at an AI-military equipment developer; victim companies absorbed at least $3 million in legal and remediation costs. That is not a corner case anymore.

41%
of enterprise IT and security leaders have already hired a fraudulent candidate
GetReal Security 2025, cited across HR Dive and Security Magazine coverage.

Why DPRK IT worker fraud specifically targets inbound mechanics

North Korean IT worker fraud is a business model engineered around one assumption: the hiring company will accept a self-nominated identity. Reverse that assumption and the model breaks.

The FBI and DOJ actions describe a repeatable pattern:

  1. A stolen or synthetic U.S. identity is used to build a resume and LinkedIn profile.
  2. An AI-enhanced headshot and a deepfake-capable interview setup pass the video screen.
  3. A U.S.-based facilitator hosts a company-issued laptop in a laptop farm so the IP geolocates correctly.
  4. The DPRK operator, working from China, the UAE, Taiwan, the UK, Romania, or Poland, logs in remotely.
  5. Salary flows back to Pyongyang, in some cases for at least 14 months before detection.

The Christina Chapman case is the reference point. The Arizona woman was sentenced to 102 months in prison for assisting North Korean IT workers in obtaining remote positions at more than 300 U.S. companies, generating over $17 million in illicit revenue for the DPRK. DOJ's coordinated response included two indictments, searches of 29 laptop farms across 16 states, and seizure of 29 financial accounts. Individual DPRK operators reportedly earn up to $300,000 annually, with funds flowing to state agencies supporting WMD and ballistic missile programs.

Every step in that chain depends on the company treating an inbound application as a trust anchor. Outbound sourcing does not have a step 1.

The DPRK model needs you to accept a self-nominated identity. Outbound sourcing does not have that step.

Outbound flips the trust model

Outbound sourcing starts from a durable, corroborated public footprint and works forward toward an outreach. Inbound starts from an unverified identity and works backward toward verification. Only one of those is defensible in 2026.

An outbound-sourced candidate arrives with artifacts that are expensive to fabricate retroactively:

  • A GitHub commit history with timestamps predating the current job market.
  • Conference talk video, recorded and indexed by the venue.
  • A LinkedIn account with continuous endorsements, mutual connections, and tenure signals across multiple employers.
  • Patents, papers, or open-source PRs merged by named maintainers.
  • Public writing indexed by search engines years before this hiring cycle.

None of these are impossible to fake. All of them are expensive to fake at scale, and they get more expensive the longer the fabrication has to survive backdating. Fraud economics collapse when the identity has to be plausible across a decade of internet exhaust, not just a 30-minute Zoom call.

This is the exact gap Refolk closes: you describe the person you want in plain English and Refolk returns a ranked shortlist built from GitHub, LinkedIn, and the open web, with the durable footprint already stitched together. The candidate is verified before you ever send a message, not after they have consumed six hours of hiring-manager time.

The in-person final round is the wrong fix

Adding an in-person final round only defends the last mile. By then the fake profile has already burned recruiter screens, take-home reviews, and hiring-manager panels. Verification belongs at sourcing, not at the airport.

The industry's current reflex is not scaling:

  • In-person interview share of roles jumped from 5% in 2024 to 30% in 2025, a 500% increase (The Interview Guys, 2026).
  • 72% of recruiting leaders now use in-person rounds specifically to fight AI fraud.
  • Only 31% of companies have deployed AI or deepfake detection software.
  • 48% of HR professionals have had zero fraud training.
  • An analysis of 19,368 AI-powered interviews between July 2025 and January 2026 flagged 38.5% of candidates for AI-cheating behavior, reaching 48% for technical roles.

Meanwhile, the attacker side is not slowing down. Cluely and Interview Coder, two invisible GPU-overlay interview-cheating tools, have over a million combined users and bypass standard screen-share detection. Enterprise deepfake detection sits at 31% deployment. That asymmetry is not closing on any timeline that helps you hire in 2026.

Flying candidates in fixes exactly one interview. Sourcing them from a verified public footprint fixes the pipeline.

The 3.5x arbitrage nobody is running

In Refolk's index of professional profiles, U.S. companies employ roughly 3.5 fraud-defense specialists for every outbound sourcer. Companies are staffing the symptom and starving the upstream fix.

Here is the shape of the labor market on both sides of this problem:

SegmentU.S. profile countTop current employerSource
Technical and Talent Sourcers1,260Anthropic, Rippling, VerkadaRefolk index
Fraud Analyst / Trust and Safety / ID Verification4,463Walmart, DraftKings, FIS, CitiRefolk index
Ratio, defense staff to sourcers3.54x-Derived
Enterprises that hired a fake candidate41%-GetReal Security 2025
Managers extremely confident in fraud catch19%-Checkr Hiring Hoax 2025
In-person interview share, 2024 to 20255% to 30%-The Interview Guys 2026
3.54x
more U.S. fraud-defense staff than outbound sourcers
Refolk index: 4,463 Fraud Analyst and Trust and Safety profiles vs 1,260 Technical and Talent Sourcers.

The named-employer split tells the story. Anthropic, Rippling, and Verkada are building outbound sourcing muscle. Walmart is stacking fraud analysts, nine of them in the top 25 profiles sampled. The offense-side companies are shrinking the surface area of the problem. The defense-side companies are trying to catch it after the fact. One of those approaches scales.

The other half of the arbitrage: the outbound-sourcer labor pool is genuinely thin. 1,260 people in the United States hold current titles like Technical Sourcer, Talent Sourcer, or Sourcing Recruiter, concentrated in the SF Bay Area at Anthropic, Rippling, Verkada, EvolutionIQ, and Fetch Rewards. You cannot hire your way out of this at industry scale. You have to give the sourcers you have leverage.

How to operationalize outbound as fraud defense

Treat outbound sourcing as a security control, not a recruiting tactic. That means putting verification at the top of the funnel and making the sourcer the first line of defense, not the fraud analyst downstream.

A working operating model looks like this:

  1. Default to outbound for any role touching production access, customer data, or regulated systems. For those roles, the inbound applicant is a candidate for review, not a candidate for interview.
  2. Require a durable public footprint at sourcing. GitHub activity, conference talks, or long-tenure LinkedIn history that predates the current hiring cycle by 24+ months. If it does not exist, escalate.
  3. Corroborate identity across at least two independent surfaces. A LinkedIn profile that matches a GitHub account that matches a talk on YouTube is expensive to fake. A LinkedIn profile alone is not.
  4. Reverse-image every candidate photo before the first interview. AI-generated headshots are the cheapest tell.
  5. Log the sourcing artifact trail in the ATS. If a candidate came through outbound, note the exact public signals. If they came inbound, flag for enhanced verification.
  6. Kill the apply-via-form path for roles above a defined risk tier. Referrals and outbound only.

Refolk fits steps 2 and 3 directly. Every profile it returns comes with the corroborated GitHub, LinkedIn, and open-web trail already assembled. Your sourcer is not manually stitching identity signals across three tabs. The verification work happens before the outreach, which is where it belongs.

What breaks if you do nothing

Two things break, in this order. First, you hire a fake. Second, your recruiting org gets restructured around cleanup instead of sourcing.

The current trajectory:

  • Fake profile share rises from today's baseline toward Gartner's projected 25% by 2028.
  • Cluely-class tools continue to outpace deepfake detection deployment, 1M+ users versus 31% enterprise deployment.
  • FBI and DOJ advisories on DPRK IT worker fraud remain active, with DPRK operatives already identified operating from the UK, Romania, and Poland, in some cases on private-company payroll for at least 14 months before detection.
  • Fraud-analyst headcount keeps growing, already 4,463 in the U.S. per Refolk's index, while the actual leverage point, outbound sourcing at 1,260 professionals, stays under-invested.

The companies that flip to outbound-default for sensitive roles in 2026 will have a two-year head start on the ones patching the last mile with in-person rounds. The DPRK operators know which pipeline is easier. So do the vendors selling GPU-overlay cheating tools to a million users. The only group still betting on inbound is the buy-side.

FAQ

Is outbound sourcing actually immune to fake-candidate fraud?

No, and anyone selling it that way is wrong. A determined adversary can build a multi-year GitHub history, plant conference talks, and cultivate a LinkedIn footprint. What outbound does is raise the cost of fraud by orders of magnitude and shift the burden of fabrication onto the attacker. Inbound asks you to disprove an identity in 30 minutes. Outbound makes the attacker fabricate a decade of internet exhaust before you ever notice them. Fraud economics do the rest.

How do I tell an AI-generated resume from a real one at sourcing?

The tell is not the resume, it is the absence of corroborating public footprint. AI-generated resumes look fine in isolation. They fail when you cross-reference the claimed employers with LinkedIn tenure, the claimed open-source contributions with actual merged PRs, and the claimed conference talks with indexed video. If two independent public surfaces do not agree, treat it as fraud until proven otherwise. This is why sourcing from durable footprints is structurally safer than reviewing a self-submitted PDF.

What roles should stay inbound?

Non-technical roles with no production access, no customer data exposure, and no regulated systems can safely stay inbound with standard verification. Everything else - engineering, security, finance, trust and safety, infrastructure, ML - should move to outbound-default. The Checkr data shows 23% of managers reporting fraud losses over $50,000. A single incident pays for a lot of outbound sourcing capacity.

How does Refolk fit into this?

Refolk is a sourcing tool built around the exact primitive that makes outbound fraud-resistant: durable public footprint across GitHub, LinkedIn, and the open web. You ask in plain English for the kind of person you need, and Refolk returns a ranked shortlist where the identity signals are already corroborated across surfaces. The verification work that used to happen after the interview happens before the outreach.

Try it on your own search

Stop building boolean strings. Just describe the person.

Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.

  • One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
  • Read live at search time, not from a database that went stale last quarter.
  • Watch every step as it runs, and see why each name made the list.

500 free credits on sign-up. No card, no demo call. See real searches.

Read next