Hiring Fraud: A CPO’s Experience Interviewing a Deep Fakeβ€”and Lessons for Businesses

Kristian McCann sits down with Magen Gicinto, Chief People Officer at Nisos, to discuss one of the fastest-growing threats facing technology companies: fraudulent job applicants linked to nation-state operations

Talent and HCM PlatformsNews

Published: July 27, 2026

Kristian McCann

AI has transformed recruitment, helping organizations automate hiring processes, identify talent more efficiently, and expand their candidate pool. However, the same technology is also empowering a new generation of fraudsters capable of infiltrating businesses through the front door. AI-generated identities, deepfake interviews, and fabricated employment histories are making it increasingly difficult for hiring teams to distinguish genuine applicants from malicious actors.

To explore the growing risk, Kristian McCann speaks with Magen Gicinto, Chief People Officer at Nisos, a company specializing in helping organizations identify and counter complex security threats. Rather than discussing a theoretical problem, Gicinto shares firsthand experience after encountering what she believes was a North Korean operative during a recruitment processβ€”an incident that highlights just how sophisticated employment fraud has become.

When Recruitment Becomes a Security Risk

Gicinto explains that the incident began like any other recruitment campaign. Nisos advertised an opening for an AI architect engineer, received numerous applications, and progressed candidates through its standard hiring process. It was only after the initial interview that subtle warning signs prompted closer scrutiny.

β€œWe had a North Korean operative that did apply that went through the normal application process,” she explains.

β€œWe were able to figure out that this was likely a North Korean operative that had applied to our position.”

The interview itself raised additional concerns. Conducted remotely over video, the individual appearing on screen did not match publicly available images associated with the candidate’s online identity. Gicinto believes the organization was likely dealing with a synthetic identity generated using deepfake technologyβ€”a tactic that is becoming increasingly accessible as AI video tools continue to improve. The experience demonstrates how traditional hiring practices, designed around trust and professional verification, can be exploited by attackers willing to invest time into constructing convincing digital personas.

Importantly, Gicinto stresses that this is no isolated incident. According to her, organizations are seeing thousands of suspicious applications and hundreds of successful placements linked to North Korean operatives. While many of these actors are seeking salaries that ultimately fund state-sponsored activities, the broader threat extends far beyond payroll fraud. Once inside an organization, fraudulent employees may gain access to source code, intellectual property, customer information, and internal communications, creating significant long-term security and compliance risks.

Looking Beyond the Resume

One of the strongest messages from the discussion is that preventing employment fraud begins long before an offer is made. Rather than relying solely on technical verification, organizations should equip recruiters and hiring managers with the knowledge to recognize suspicious patterns throughout the hiring journey.

β€œIt starts with just education,” Gicinto says.

β€œMake sure that your hiring teams, your talent acquisition teams, your HR teams, even your hiring managers are aware of this problem… It is a business risk.”

Many of the warning signs she describes are individually subtle but collectively revealing. AI-generated resumes that mirror job descriptions unusually closely, recently created LinkedIn profiles claiming extensive work histories, inconsistent profile photographs across online platforms, and candidates who appear heavily dependent on off-screen prompts during interviews may all warrant further investigation. Likewise, applicants who repeatedly change shipping addresses for company equipment, frequently update banking information before starting work, or demonstrate skills that fail to match their claimed experience should prompt additional verification.

As AI-generated content becomes increasingly convincing, Gicinto believes organizations must also evolve their defenses. Identity verification will become just as important as employment verification, ensuring candidates are genuinely who they claim to be before they are granted access to corporate systems. This shift represents a broader change in recruitment, where validating digital identity is becoming as fundamental as assessing qualifications and experience.

Building Resilience for an AI-Driven Future

The conversation ultimately reinforces that employment fraud is no longer simply an HR concern. It represents a growing enterprise-wide security challenge requiring collaboration between recruitment, human resources, IT, and cybersecurity teams. Organizations that continue to view hiring solely as a talent acquisition function risk overlooking one of the earliest opportunities to prevent compromise.

While today’s attacks are concentrated primarily around remote technology roles, Gicinto expects the threat to expand into industries handling increasingly valuable intellectual property and critical infrastructure. Sectors such as cryptocurrency, biotechnology, defense, and infrastructure may become particularly attractive targets as attackers seek access to highly sensitive information rather than simply employment income.

For organizations embracing AI to improve hiring, the interview serves as an important reminder that technology alone cannot solve every challenge. Human awareness, structured verification processes, and continuous education remain essential. As deepfake technology and synthetic identities become more convincing, building resilience into recruitment processes will be just as important as securing networks or protecting endpoints. In an AI-driven hiring landscape, knowing exactly who is joining the organization may prove to be one of the most important security decisions a business makes.

Generative AITalent Acquisition SoftwareTalent Marketplace
Featured

Share This Post