It was a Tuesday morning in March 2024 when a mid-sized fintech company in Austin, Texas onboarded a new senior developer. He had aced three video interviews, submitted a polished GitHub portfolio, and passed a standard background check. Six weeks later, the FBI knocked. The “developer” was a North Korean IT worker operating from a laptop farm overseas, funneling his salary back to a sanctioned state program. The hiring team never met a real person. Not once.
This is not a fringe story anymore.
The FBI issued a formal advisory in May 2024 warning U.S. employers that North Korean operatives are actively applying for remote tech jobs using AI-generated faces, voice changers, and stolen American identities. And here is the part that should make you stop scrolling: the screening tools most companies use were not built to catch any of this.
Why Your Current Screening Process Is Already Obsolete
Standard background checks verify a Social Security number against a database. They do not verify that the person on the video call is the person who owns that number. Those are two completely different problems, and most HR departments are only solving one of them.
Think of it this way: a background check is like verifying a car’s VIN number without ever looking at the car. The paperwork can be spotless while someone drives off in a vehicle they stole.
Ask yourself this honestly: if someone handed your team a deepfake resume, a cloned LinkedIn profile, and an AI-generated face that moved naturally on a Zoom call, how many rounds would they survive?
The fraud is not clumsy. No pixelated Zoom backgrounds. No bad accents. Tools like HeyGen and ElevenLabs can generate real-time face-swapping and voice synthesis that fools the human eye and ear. A 2023 iProov report found that attacks using AI-generated faces increased by 704% in the second half of 2023 alone. Seven hundred and four percent in six months.
Warning: Standard ATS platforms like Greenhouse, Lever, and Workday have no built-in biometric verification by default. You have to activate it separately, and most teams never do. Check your security settings page today.
The Tools That Are Actually Catching Fakes Right Now
Here is what I found after digging through vendor documentation, security researcher breakdowns, and actual case studies so you do not have to.
1. Liveness Detection Platforms (iProov, FaceTec)
These tools do not just check if a face looks real. They check if a face is physically present in real space. iProov’s Genuine Presence Assurance technology sends a randomized light sequence at the candidate’s face and measures how light reflects off three-dimensional skin. A flat screen displaying an AI-generated face fails immediately. FaceTec does something similar using depth-mapping.
2. Behavioral Biometrics (Behavioral Signals, Pindrop)
These tools analyze how someone types, pauses, and responds during a conversation. They track response latency, keystroke rhythm, and vocal stress patterns. Pindrop’s platform flags calls where voice patterns suggest synthesis rather than a human larynx. Behavioral Signals goes further, analyzing the emotional arc of a conversation to detect scripted or bot-driven responses.
3. AI Writing Detection with Document Screening (Originality.ai, Turnitin for Business)
Resumes and cover letters generated by ChatGPT or Claude have detectable statistical patterns. Originality.ai scores documents on a 0-100 scale and flags likely AI-generated text. It is not perfect. No detector is. But used as a screening layer for written submissions, it catches the lazy end of the fraud spectrum.
4. Live ID Verification with Selfie Match (Persona, Jumio)
Persona and Jumio require candidates to submit a government-issued ID and take a real-time selfie. The system then matches the selfie to the ID photo using facial recognition. It is the closest thing to actually asking someone to show their face at a front desk, adapted for remote hiring.
5. Reverse Image Search and OSINT Tools (PimEyes, Social Catfish)
Free and low-cost options still matter. Running a candidate’s profile photo through PimEyes checks whether that image appears anywhere else online under a different name. Social Catfish allows reverse-searching email addresses, phone numbers, and images simultaneously. Takes five minutes. Catches sloppy fraud fast.
Did You Know: The LinkedIn profile photo of an AI-generated candidate often shows no consistent aging across photos, no tagged appearances in group shots, and no image history predating the account creation date. These are manual red flags any recruiter can learn to spot in under a week.
Honest Pros and Cons: What These Tools Get Wrong
None of this is a clean solution. Here is the unfiltered version.
False positives are real. Originality.ai and similar text detectors have flagged native English speakers with concise, structured writing styles. A non-native English speaker who writes formally may score high for AI likelihood simply because of sentence construction patterns. That is a bias problem, not a fraud problem.
International candidates face the most friction. Biometric liveness detection tools can struggle with certain skin tones and lighting conditions in regions where home office setups lack good equipment. A legitimate developer in Lagos or Jakarta may fail a liveness check that a fraudster running quality hardware in a controlled environment passes. That is a serious equity concern and one most vendors still have not solved credibly.
Cost is a real barrier. Enterprise-tier biometric tools from iProov and Jumio are not cheap. Pricing is largely quote-based, but security researchers consistently estimate deployment costs for mid-market companies in the range of tens of thousands of dollars annually. That is out of reach for most startups doing early hiring.
Legal grey zones exist and they are not small. Illinois’s Biometric Information Privacy Act (BIPA) and Texas’s Capture or Use of Biometric Identifier statute both place strict requirements on how biometric data can be collected, stored, and disclosed. If you collect a candidate’s facial geometry data during a liveness check and your vendor stores it without proper disclosure, you may be exposed to litigation. Get your legal team involved before you deploy any biometric screening tool.
Pro Tip: Before signing any biometric verification vendor contract, ask them directly: where is candidate biometric data stored, for how long, and under which jurisdictional law? If they hesitate or send you to a generic privacy policy, walk away.
Why HR Teams Resist These Tools (And How to Make the Internal Case)
There is a real organizational pull to not look too hard at problems you are not ready to fix. It is not laziness. It is rational self-protection. If your team starts actively screening for AI-generated candidates and finds them, you now have a documented problem your leadership must respond to. Some HR leaders would rather not open that door.
That resistance is understandable, but it is also exactly what fraudsters count on.
The internal case is simpler than most people think. You do not need to pitch a biometric overhaul to your CHRO on day one. Start with a low-cost written document screening layer. Add a single behavioral interview question that requires a specific, personal, recent experience with a named tool. Build the evidence base. Then escalate.
Have you ever stopped mid-hire and thought, this person is too frictionless? No confusion about the role, no questions about the team, no personality at all just clean, structured answers that technically cover every requirement? That feeling is your gut noticing something your process has no mechanism to flag. Trust it. Then build the mechanism.
An imperfect screening layer that is deployed and running beats a perfect one that is still in a procurement review six months from now. Done is not the enemy of good here. Waiting is.
Your Next 3 Steps
Step 1: Sign up for Originality.ai ($14.95 per month) and run your last five candidate cover letters and take-home assessments through the detector this week. It takes under 10 minutes to set up and gives you an immediate baseline on what your current applicant pool looks like.
Step 2: Add one specific, experience-anchored question to your next job posting or screening call. Something like: “Describe a bug you personally fixed in the last 60 days. What was the error, what tool did you use, and what did the fix actually look like in code?” AI-generated answers cannot fake lived specificity. Scripted fraud collapses under follow-up.
Step 3: Log into your current video interview platform (whether Greenhouse, Lever, HireVue, or another) and navigate to the security or identity verification settings today. Check whether biometric liveness detection is available and not yet activated. If it is sitting there unused, activate it or flag it to your security team by end of week. If it is not available, request a formal quote from Persona (persona.com) and bring the cost comparison to your next hiring review with the FBI advisory attached as context.
