A Polish security startup got two interviews deep with a backend engineer before anyone noticed the candidate's face wasn't moving like a face. The tell wasn't a resume gap or a bad reference. It was a refusal to hold a hand up in front of the camera. Remote hiring has become an identity problem, and most teams are still verifying employment history while the actual fraud is happening live on screen. If you hire people you never meet in person, you need a repeatable way to verify a job candidate's photo and video before that person gets a laptop, a VPN token, and a seat in your Slack.

The short version
Run three layers. Check the headshot first with a reverse image search plus metadata and error level analysis, which tells you whether the file came out of a camera or came out of a generator. Then use live movement tests during the interview, because current face-swap tools still stumble on hand occlusion, hard profile turns, and unscripted follow-up questions. Finally, put all of it in a written policy applied to every candidate for the role, since biometric and AI-analysis laws in states like Illinois carry real penalties for verification done casually.

Fake Candidates Stopped Being a Rare Story and Became a Volume Problem

This is not an odd incident you deal with if it ever shows up. It is a background rate you should assume is already in your pipeline. The economics changed: creating a convincing fake applicant used to take skill and time, and now it takes neither.

1 in 4 job candidate profiles worldwide could be fake by 2028, according to Gartner

The supporting numbers are just as blunt. In a Gartner survey of 3,000 candidates, 6 percent admitted to interview fraud, meaning they either posed as someone else or had someone pose as them. A Resume Genius survey of 1,000 US hiring managers found roughly 17 percent had already run into a candidate using deepfake technology in a video interview. Palo Alto Networks has estimated that someone with no image editing experience can build a fake interview persona in about 70 minutes.

The motives split into two groups that need different responses. Some fakers are ordinary people gaming the process with a stand-in for the technical round or a helper feeding answers off camera. The other group is organized. The FBI has documented more than 300 US companies that unknowingly hired North Korean operatives using stolen identities, and Amazon's chief security officer has said the company blocked over 1,800 suspected North Korean applicants since April 2024. The first group costs you a bad hire. The second costs you a breach notification.

Start With the Headshot, Because It Costs You Four Minutes

Do the cheapest check first, before you spend anyone's calendar time. A candidate photo is a file, and files carry evidence. You can learn more in four minutes with a headshot than you will in a thirty minute screening call.

Start with a reverse image search. Drop it into Google Lens, TinEye, and Yandex, since they index different corners of the web and regularly disagree. If the face appears on a stock photography site, a modeling portfolio, or someone else's social profile under a different name, you are done. If it appears on several unrelated professional profiles with different names, that is a synthetic identity kit being reused across applications. And if it returns nothing at all, that is not a clean bill of health, because a face generated this morning has no history to find.

A common mistake I notice: teams run the reverse search on the LinkedIn thumbnail. That version has been resized, recompressed, and stripped by the platform, which wrecks the match quality and everything you would check next. Ask for the original file instead, and keep the request administrative: you need a print-quality headshot for the internal directory. Anyone real sends it without a second thought.

What Image Metadata Actually Tells You About a Candidate's Photo

Metadata is strong evidence when it is present and almost no evidence when it is missing. Get that asymmetry right and this becomes a useful check instead of a source of false accusations.

When EXIF data survives, a real photo looks like a real photo: a camera or phone model, a lens, an aperture and shutter speed, a capture timestamp, sometimes GPS coordinates. Those fields are boring and internally consistent. The interesting one is Software. A headshot listing an image editor, or carrying generator tags from a text-to-image tool, has been through a pipeline no ordinary portrait needs. A capture date sitting suspiciously close to the application date is worth a note too.

Now the part most hiring guides skip. Missing metadata is not a red flag on its own. LinkedIn, WhatsApp, Slack, iMessage, and most applicant tracking systems strip EXIF on upload for privacy reasons, so a perfectly honest candidate will hand you a naked file constantly. Treat an empty metadata panel as a reason to ask for the original, not as a finding. If you write "no metadata" in a candidate record as though it means something, you have created a document you will regret.

How to Verify a Job Candidate's Photo and Video With Error Level Analysis

Error level analysis reads the compression history of a JPEG and shows you where different parts of the image have been saved a different number of times. It will not hand you a verdict. It will tell you where to look harder, which is more than a human eye can do on a 400 pixel headshot.

The mechanism in plain terms: every time a JPEG is saved it throws away a little detail, unevenly across the image. If someone pastes a different face onto a real photo, that region has been through a different number of save cycles than the background, and ELA renders the difference as brightness. A face glowing against a flat dark background, or a rectangular patch of uniform error where a jawline should be, means that region has its own history.

Error level analysis result
Error level analysis result

Be honest about the limits, because overselling this is how teams end up wrong and confident. A fully AI-generated image saved once looks uniform, since nothing was pasted into anything. Heavy recompression flattens everything into noise, and screenshots destroy the signal entirely. ELA is a pointer, not a verdict, and it needs the original file.

If you want to try this on a real candidate photo right now, you can upload the JPG here and see the ELA and metadata output in a few seconds. It is free and it takes less time than reading the resume attached to it.

The Live Video Checks That Still Break Most Deepfakes

Real-time face swap software is good at a talking head facing the camera and bad at almost everything else. Your job in a video interview is to leave that comfortable zone as early and as casually as possible.

The occlusion test is the one that went viral for a reason. Vidoc Security Lab co-founder Dawid Moczadlo asked a candidate to place a hand partially in front of his face. The candidate raised his hand beside his face instead, never crossing it, and then refused outright. Moczadlo ended the call. Overlay models struggle when something passes between the face and the camera, producing a smear, a flicker, or a hand that briefly vanishes at the edges. The refusal told him more than the test would have.

A candidate who passes the hand test isn't verified. They just aren't running last year's software.

Add three more, and spread them across the call so they feel like conversation rather than an exam. Ask for a full profile turn, roughly ninety degrees, because face-swap models are trained mostly on frontal images and the illusion thins out at the edges of the head. Ask them to stand up and angle the laptop to show the room, which is awkward for a static background and impossible for a virtual one. And read out a sentence you invent on the spot for them to repeat, which breaks anything pre-recorded and exposes lip-sync drift.

Watch the conversation just as closely, because the proxy setup is more common than the deepfake. Someone answering with a chatbot off screen has a distinctive rhythm: a beat of silence, eyes tracking sideways, then a fluent and slightly generic paragraph. Break it with follow-ups tied to specifics: which part of that project would they rebuild, and who pushed back? A real engineer has an opinion and a grudge. A reader has a pause.

One caveat that matters more each quarter: occlusion handling is improving fast. Treat these tests as filters that catch the current crop of tools, not as clearance.

Read the Whole Application, Not Just the Face

Identity fraud leaves paperwork traces long before it reaches your camera, and paperwork is easier to check than pixels. The strongest signals are almost never dramatic.

Start with the address. In the Vidoc case, the address on the CV belonged to a public institution. Mail drops, coworking spaces, and buildings that make no sense as homes recur in these schemes, because the laptop has to reach somewhere the operator controls. Then check the LinkedIn profile's age and shape: created recently, few mutual connections, endorsements from other thin profiles, a work history at companies that are hard to verify.

Watch onboarding requests most of all. Equipment redirected to a new address, a bank account in a country that doesn't match the stated residence, or payment details changed after the offer letter are the highest-signal moments in the whole process. Flag reference emails from free domains too, especially when the manager writes with the same quirks as the candidate.

Where These Checks Belong in Your Hiring Funnel

Verification is cheap early and expensive late. Every check you push to the offer stage is a check you pay for in wasted interview hours. Spread them across four points instead of stacking them at the end.

At application, run the reverse image search and the metadata and ELA pass on the headshot. That is fast enough to batch alongside resume screening. At the first live call, require cameras on and work in two movement checks. At offer stage, run a government ID check against a live capture using a vendor that does real liveness detection, not a photo of a document. On day one, ship the device only to the verified address and open with a camera-on session where the new hire holds up that same ID.

Track what this actually costs you before you defend it internally, because someone will ask. Even a basic spreadsheet can help. Track how many applicants fail each verification step, how many interview hours are avoided, and the estimated cost per interview. After a few hiring cycles, you'll have real data to justify the process instead of relying on assumptions.

Run This Without Treating Every Applicant Like a Suspect

This is where most teams create a second problem while solving the first. Verification applied unevenly is not security, it is a discrimination claim with a paper trail. The fix is uniformity, disclosure, and knowing which laws you just walked into.

Uniformity means every candidate for a role gets the same checks in the same order, written into the interview guide. The moment a check is triggered by an accent, a name, or a country, you have built something indefensible. Disclosure means telling candidates up front what you verify and why. Gartner recommends this, and it has a useful side effect: people committing fraud tend to withdraw once they read the process.

The legal exposure is real and it varies by state. Illinois is the sharp end. Its Artificial Intelligence Video Interview Act requires notice, an explanation of the technology, written consent before AI analyzes a video interview, and destruction of recordings within 30 days of a hiring decision. The Biometric Information Privacy Act covers facial geometry and carries a private right of action, and in Deyerler v. HireVue a federal court held that complying with one statute does not satisfy the other.

Texas, Washington, California, and New York have their own biometric rules. A human asking someone to turn their head sits in a different legal position than software measuring facial geometry, which is worth knowing before you buy a tool. I write about image forensics, not employment law, so run your process past counsel.

Before you roll this out
Write the verification steps into the interview guide for the role, not into a Slack thread. Add a plain-language line to your job postings and interview invitations describing what you check. Decide in advance how long you keep candidate photos, recordings, and ID images, and set that retention to the shortest period you can defend. Then have counsel read it once.

What to Do When Something Comes Back Suspicious

One flag is a question, not a conclusion. Missing metadata, a stiff camera presence, or a reverse search that returns nothing are all things that happen to honest people every day. Your response should be a next step, not an accusation.

On the call, say nothing conclusive. Finish the interview normally, then write down what you saw in factual terms with timestamps: the candidate declined the requested gesture, audio led video by roughly half a second. Observations survive scrutiny. Conclusions do not. Preserve the original files, and if you record interviews, confirm you had consent under your own policy.

Then escalate to security and HR together rather than either alone, and route the candidate into your standard identity verification step, framed as policy rather than suspicion. If they are real, they complete it and you have insulted no one. If the pattern points to organized fraud, report it to the FBI's Internet Crime Complaint Center and involve legal early, given the sanctions exposure attached to these schemes.

Observations survive scrutiny. Conclusions do not.

Questions Hiring Teams Keep Asking

Can I tell a candidate's headshot is AI-generated just by looking at it?
Rarely, and not reliably since about 2024. The old tells like mangled ears, warped glasses frames, and background text that dissolves into symbols still appear in low-effort fakes, but current generators clear all of them. Analyze the file rather than the face: reverse image search, metadata, and error level analysis, in that order.
Is missing metadata proof that a photo is fake?
No, and treating it that way will burn good candidates. Almost every platform strips EXIF on upload, so a stripped file is the normal case, not the exception. Missing metadata means you should request the original file, nothing more.
Do the live video tests actually still work?
Partially, and less well every quarter. Hand occlusion, sharp profile turns, and unscripted follow-ups still cause visible failures in most consumer face-swap tools, but the software is improving quickly. A refusal to attempt the test remains far more informative than the result of it.
Can we require government ID from every applicant?
At offer stage, generally yes, since you already collect identity documents for employment eligibility. At the application stage it is much riskier, both legally and for your conversion rate. Apply it uniformly to everyone in the role, collect the minimum you need, delete it on a schedule, and check your local rules first.

Where to Start This Week

Pick your three riskiest open remote roles, the ones with production access or customer data. Add two things to those pipelines by Friday: a reverse image search and metadata pass on the headshot at screening, and two live movement checks written into the first-round interview guide so every interviewer runs them the same way. That is an afternoon of work, and it closes the gap most fake candidates walk through.

The rest can follow over a quarter: the ID and liveness check at offer stage, tighter equipment shipping rules, and the whole process written down and reviewed by counsel so it stays uniform. None of it requires a budget line to begin.

If you have a candidate headshot open in another tab, start there. Upload the JPG and read the error level analysis and metadata output before you send the calendar invite. It takes seconds, costs nothing, and it is the fastest check available to a team that hasn't started any of this yet.