The hiring landscape has transformed dramatically as employers grapple with an explosion of fraudulent applications and AI-generated submissions. No longer satisfied with resume screening alone, companies are now requiring job applicants to submit to biometric facial scans, submit to scrutiny of their email histories, and even turn their webcams toward electrical outlets during Zoom interviews to prove their physical location. This arms race against deception reveals how deeply artificial intelligence has penetrated the recruitment process and the lengths organisations will go to protect themselves from sophisticated identity fraud.
The scale of the problem has become impossible to ignore. According to hiring software firm Greenhouse, more than one-third of approximately 1,230 headhunters and hiring managers now dedicate half their working week to filtering out "spam and junk" submissions, with many of these applications generated by AI systems. The concern extends beyond spam: companies are increasingly worried about applicants deploying stolen or fabricated identities to improve their chances of landing positions. Gartner analyst Hiten Sheth reports that his clients have encountered candidates using deepfakes to impersonate someone else during video meetings, and in one alarming case, a recruiter interviewed one person only to have an entirely different individual show up on the first day of employment. Another company hired what they believed was a remote worker based in North America, only to discover the person actually resided on a different continent. Based on these troubling trends, Gartner now projects that one in four job applications companies receive will be fraudulent by 2028.
The financial consequences of hiring fraud are substantial and measurable. Approximately 23% of US companies surveyed by background-check provider Checkr reported that hiring fraud cost them more than US$50,000 in the past year through delayed projects, compliance issues, and the expense of rehiring. For one in ten companies, losses exceeded US$100,000. These figures do not account for reputational damage or the disruption caused when unvetted employees gain access to company systems and confidential information. The problem is particularly acute because many businesses have historically shared sensitive information about staff, workflows, and operations with job candidates before even requesting identification or conducting background checks.
Susan Dietrich, owner of Pittsburgh-based staffing firm Tops Staffing, exemplifies the new hiring reality. She now employs a combination of AI tools and telephone interviews to verify candidate identities and validate their claimed experience. Her team has discovered job seekers who claimed to accumulate years of work experience in the mere months since their last application through her firm. Others listed technical skills on their resumes that they demonstrably knew nothing about when questioned during phone interviews. After thorough evaluation, Dietrich's team produces detailed summaries of what they were able to independently verify, a process that, she acknowledges, consumes substantial time and resources.
Identity verification companies have flourished in response to these challenges. Clear, best known for enabling airport passengers to skip security lines, expanded its digital platforms during the past year to help both large corporations and small businesses identify deceptive applicants. Brett Romanoff, executive vice president of Clear1, the company's digital-identity division, explained that the company did not initially set out to address hiring fraud. However, after some customers began using the service to vet already-hired remote workers, Clear integrated biometric facial scanning technology to validate job applicants during the early stages of recruitment. Similarly, Persona, another identity-verification firm, reports that confirming the identities of prospective hires has become one of its fastest-growing service lines.
Persona's screening platform demonstrates the sophisticated technical capabilities now deployed in hiring. The system can detect if a candidate is writing from a newly created email address or if their computer's clock displays a different time zone than their claimed location. It flags whether applicants are using virtual private networks to obscure their geographic location, and it identifies when IP addresses jump across the globe at physically impossible speeds. In one documented case, Persona's client discovered a prospect impersonating a Coinbase employee using details lifted directly from the employee's verified LinkedIn profile. Rick Song, Persona's chief executive officer, emphasises that the real risk in hiring is not merely someone's past experience or background, but rather whether they are authentically who they claim to be.
These verification measures represent a fundamental shift in hiring methodology. Traditional background checks operated retrospectively, focusing on an applicant's employment history and previous conduct. The new approach instead examines the signals and metadata generated by the devices candidates use to apply, their network location data, and their behaviour patterns during the application process. At a recent conference for human resources professionals hosted by the Society for Human Resource Management, recruiters described using biometric screening tools to "stalk" candidates in virtual interviews and tracking IP addresses long before conducting traditional background checks. Stephen Dwyer, president of the American Staffing Association, observed that the practice "almost sounds like something out of a spy novel."
Some of these tactics have become unusual enough to warrant explicit instruction. Dwyer is now training recruiters at American Staffing Association member firms on a range of precautions to confirm applicants are authentically who and where they claim to be. One surprisingly common tactic involves asking interviewees to aim their webcam at a nearby electrical outlet as proof they are physically located in the United States. More than 40% of employers who hire temporary workers now deploy some form of identity-verification software, according to the first industry survey by Staffing Industry Analysts, which gathered responses from more than 120 companies. Companies including private lender Kiavi require candidates to complete "biometric and device validation to confirm identity and liveness," while data centre giant Equinix asks applicants to present government-issued photo identification at the beginning of video interviews and prohibits the use of virtual backgrounds.
The acceleration of fraudulent applications coincides with significant changes in the employment landscape. Hiring has decelerated, and job searches are consuming considerably more time. The median unemployed worker now spends eleven weeks searching for a job, up from ten weeks a year earlier according to US Labor Department data. Facing extended unemployment, some job seekers have resorted to extreme measures, including impersonating others or deploying chatbots to assist during interviews. The situation has grown so serious that the Justice Department disclosed last year that North Korean operatives had infiltrated more than 100 US companies by successfully convincing them to hire the operatives for remote IT positions. NBCUniversal, Nike, and Boeing all unknowingly hired North Korean nationals who used fake identification documents and falsified resumes to pose as American workers.
For Southeast Asian readers, these developments carry particular significance. As remote work becomes increasingly normalised and regional hiring practices globalise, the fraud detection methods being pioneered by American companies will likely spread to Malaysian and regional employers. Many Malaysian firms already employ remote workers across Southeast Asia, making them vulnerable to the same identity fraud schemes affecting Western companies. The proliferation of AI-generated applications and deepfake technology poses risks that transcend borders. Additionally, as Malaysian companies expand their recruitment to international talent pools, particularly for IT and technical roles, they will face mounting pressure to implement similar verification measures. This trend will likely increase compliance costs for employers and friction for legitimate job seekers, who may resent the invasive nature of biometric scanning and location tracking.
Ernest Stephens, a talent-acquisition manager at Seattle Public Utilities, summarises the stakes succinctly. He describes the rise in falsified information as "one of the greatest threats to us," forcing his organisation to implement "a lot of changes" to the hiring process, though he declined to elaborate due to security concerns befitting a public utility. Holly Priestner, chief people officer at real estate company Place, noted that her organisation learned important lessons "the hard way." Seven months ago, Place began requiring all applicants to verify their identities through Clear using government-issued identification and a selfie. The platform now flags hundreds of potentially suspicious applications daily. Similarly, Equifax found that nearly three-quarters of more than 350 human resources officials reported encountering "challenges with fabricated or misleading candidate information." As these technologies become standardised across industries, the boundary between legitimate security and excessive surveillance continues to blur, raising questions about privacy, fairness, and the future of recruitment in an age of artificial intelligence.
