
Excerpted from a Whiteford Law Blog by Lisa Brauner
Deepfakes have shifted from novelty to real risk for employers. Some identity fraud research indicates that overall deepfake and synthetic identity fraud attempts targeting organizations have surged globally. According to a report by GetReal Security, 41% of IT, cybersecurity, risk and fraud leaders say their company has hired and onboarded a fraudulent candidate.
Recent reports detail this growing trend of remote interviewees using synthetic video and voice to pass identity checks, while security researchers and training providers have documented cases of imposters attempting to infiltrate U.S. companies as “IT workers.” The FBI has warned of a rise in deepfake-enabled fraud in remote hiring, and high-profile incidents show how convincingly AI can simulate live presence, senior executives and credentialed professionals.
In addition to a public service announcement on December 19, 2025, warning about the rise in AI deepfake impersonation, on July 31, 2026, the U.S. State Department and FBI, together with multiple countries’ foreign affairs and other government offices, issued a joint alert to countries, U.S. businesses and other entities, notifying them that the North Korean government has deployed IT services workers to obtain false identities and remotely earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs.
According to the joint alert, “these workers seek out contracts with the intent of remitting their salaries to their parent North Korean agencies. They also pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft and theft of sensitive information.” North Korea is a sanctioned jurisdiction, of course, meaning that U.S. companies are prohibited from employing workers from North Korea.
Case in point: The cybersecurity awareness training company KnowBe4 — which trains companies on how to avoid getting hacked — hired a deep-fake job applicant as a software engineer. The fake job applicant used the stolen identity of a U.S. citizen when applying for the job, enhanced by AI, and had four video interviews while using AI-deepfake technology.
The fake job applicant was a North Korean government operative. Once hired, he requested to have his laptop shipped to an address that was, in fact, an “IT mule laptop farm.” He then used a VPN from North Korea or China and unsuccessfully attempted to hack into KnowBe4’s computer systems to plant malware, before his actions were discovered by KnowBe4.
What Should Employers Do Now?
Here are just a few practical suggestions to help mitigate the risk of deepfakes and when to call legal counsel.
- Conduct candidate interviews in-person.
- Standardize identity assurance at every hiring stage with layered controls.
- Verify references independently by telephone, not just email, and cross-check LinkedIn or other professional networks.
- Background checks should cross-verify information from multiple sources.
- Require new hires to meet their supervisors and/or HR in-person, and where permitted by law, use geolocation verification and required check-ins for remote workers.
- Train your internal recruiters to spot “red flags” in job candidates interviewing by video to identify and respond to such tactics, including such things as audio and video not syncing, seemingly scripted answers, refusal to perform real-time gestures such as looking up and looking down while on camera, and then escalate your concerns to security, legal and compliance.
- Call employment counsel immediately if a candidate fails identity checks, you plan to withdraw a conditional offer, you see indicators of a sanctions nexus, or any adverse action you plan to take that relies on biometric or identity-proofing results.
For the full story, please click here.