Candidate fraud used to mean an inflated job title or a stretched employment date. It now means AI-generated applications arriving by the thousands, fabricated resumes that read better than real ones, coached reference rings submitting feedback from a single IP address, and proxy candidates showing up to interviews. The problem has grown so quickly that Kyle & Co., the research and advisory firm founded by industry analyst Kyle Lagunas, released a full report on it this summer: The State of Candidate Fraud Detection & Prevention.
In November, Lagunas will deliver the opening keynote at the ERE Recruiting Innovation Summit, and the day before, he will facilitate the RIS Executive Forum, an invitation-only working session for senior TA executives on AI in talent acquisition. I spoke with Lagunas about the report, which began as a follow-up to the firm’s AI interviewer research and kept expanding as the team pulled at the thread.
Lagunas traces the problem to what he calls a perfect storm: “automating a lot of decision-making before we were fine-tuning it, and also downsizing a lot of our human workforce at the same time as we were also increasing our virtual interviewing,” he said, recalling his reaction at the time: “This is going to be really problematic. And it has proven to be.”
The report maps a spectrum of fraud that runs from resume embellishment to outright crime, a range Lagunas calls lowercase fraud and uppercase Fraud. “Some candidates are intentionally inflating their experience and creating completely fake resumes, but they’re doing it just to get a job. They’re not doing it in order to scam you.” At the far end sit the criminals. “There are the other ones that are trying to literally get access to sensitive systems and information.”
KnowBe4, the security awareness training company, hired a North Korean operative posing as a U.S.-based software engineer in July 2024. Using a stolen American identity, he passed multiple interviews, a background check, and reference verification, and was caught only when endpoint security software flagged him attempting to install malware after receiving his company workstation. Cases like that are the rare extreme, a small slice of overall candidate fraud. Most of what recruiters encounter every day sits far closer to the lowercase end of the spectrum.
The lowercase version is not just a problem of separating the real from the embellished, but also a candidate experience problem the profession has not begun to address. “There’s a social contract that we have with candidates that is not established yet,” Lagunas said. He challenged me to name career sites that tell candidates how the employer expects them to use AI and what uses it will reject. I could not name one. Neither could he.
The uppercase version is a security problem, and the early technical fixes are backfiring. Lagunas described a conversation with the head of assessment at one of the world’s largest tech companies, which had turned on an ATS feature that flagged fraud signals like suspicious IP addresses and email addresses. “It was creating so many false positives that the signal became useless, but worse than useless,” he said. “Hiring managers would see a signal of this may be fraud, and they were immediately like, oh, that’s fraud, like this is a fraudulent candidate, instead of looking at it a little bit more critically or just being circumspect. It was introducing more layers of bias into the process, and it didn’t work.”
The report identifies nine stages of the hiring lifecycle where fraud enters. That is a lot of doors to lock, but adding headcount alone doesn’t help. “Resources alone are not the solution. It really is more of intentionality and process design,” he said. “You can redesign your process if there’s one person in the team or one million people in the team.”
Some of the redesign is as simple as reading the fine print of the reference check. “Require references, look at the IP addresses of those people, and look up the phone numbers of those people,” he said. “Typically people aren’t being that sophisticated with their references. You’ll see three references all from the same IP address.” The report calls the IP address and device fingerprint of a candidate’s references the most reliable and least gameable fraud signal in the market.
Some of the fix costs money that TA teams cut years ago, with budget returning for in-person interviews. Lagunas calls this smart friction, deliberate slow points in a process that has been optimized for nothing but speed. “We really just went to move as fast as we could with as few human resources as possible,” he said of the first wave of AI adoption. “We’re automating the things that never got optimized, and that’s another vulnerability for us.”
The biggest surprise in the research was the organizational vacuum around fraud prevention. “CISOs don’t really want this. They are not grabbing this away from TA,” Lagunas said. Nobody claiming the problem is worse than the problem itself. “When nobody owns it, you can’t create accountability. You can’t create standards. You can’t get commitment.”
Lagunas expects ownership to land with the fastest-growing team in recruiting. “I won’t be surprised if it becomes a part of the RecOps gig,” he said. “I don’t think that it should be living completely outside of our space. It should be something that’s connected to the work that we do.”
No single tool stops candidate fraud. The best practice emerging from the research is layered defense: top-of-funnel filters to catch the obvious fakes, identity verification deeper in the funnel, and human diligence covering the seams.
Products like Greenhouse’s CLEAR identity verification partnership are emerging to address different types of fraud, though no single product can do it all. Even a verified ID has limits, as Lagunas noted: “you can still spoof a driver’s license.”
For leaders starting from zero, Lagunas has some advice.
“Doing something is better than nothing.”