Articles

Employment Law Update: Are You For Real? An Increase in AI Deepfake Job Candidates and Employees Raises “Red Flags” for U.S. Employers

Date: September 17, 2026
Deepfakes have shifted from novelty to real risk for employers. Some identity fraud research indicates that overall deepfake and synthetic identity fraud attempts targeting organizations have surged globally. According to a report by GetReal Security, 41% of IT, cybersecurity, risk and fraud leaders say their company has hired and onboarded a fraudulent candidate.

Recent reports detail this growing trend of remote interviewees using synthetic video and voice to pass identity checks, while security researchers and training providers have documented cases of imposters attempting to infiltrate U.S. companies as “IT workers.” The FBI has warned of a rise in deepfake-enabled fraud in remote hiring, and high-profile incidents show how convincingly AI can simulate live presence, senior executives and credentialed professionals.

In addition to a public service announcement on December 19, 2025, warning about the rise in AI deepfake impersonation, on July 31, 2026, the U.S. State Department and FBI, together with multiple countries’ foreign affairs and other government offices, issued a joint alert to countries, U.S. businesses and other entities, notifying them that the North Korean government has deployed IT services workers to obtain false identities and remotely earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs.

According to the joint alert, “[t]hese workers seek out contracts with the intent of remitting their salaries to their parent North Korean agencies. They also pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft and theft of sensitive information.” North Korea is a sanctioned jurisdiction, of course, meaning that U.S. companies are prohibited from employing workers from North Korea. The FBI has reported further that eight individuals have been sentenced to prison in 2026 alone for their roles in these schemes.

Case in point: The cybersecurity awareness training company KnowBe4 — which trains companies on how to avoid getting hacked — hired a deep-fake job applicant as a software engineer. The fake job applicant used the stolen identity of a U.S. citizen when applying for the job, enhanced by AI, and had four video interviews while using AI-deepfake technology.

The fake job applicant was a North Korean government operative. Once hired, he requested to have his laptop shipped to an address that was, in fact, an “IT mule laptop farm.” He then used a VPN from North Korea or China and unsuccessfully attempted to hack into KnowBe4’s computer systems to plant malware, before his actions were discovered and thwarted by KnowBe4. 

There was also the notorious case of the finance employee in Hong Kong who was duped on a work video call by a deepfake “CFO” and deepfake “colleagues,” and wired roughly $25 million to criminals who had created the deepfake video and voice replication of the employee’s CFO and colleagues.
 

What Should Employers Do Now?

Here are just a few practical suggestions to help mitigate the risk of deepfakes impacting your workplaces and when to call legal counsel.
 
  • Treat deepfake hiring as both a security and legal exposure.
  • Conduct candidate interviews in-person, whenever possible.
  • Standardize identity assurance at every hiring stage with layered controls.
  • Verify references independently by telephone, not just email, and cross-check LinkedIn or other professional networks to verify employment history and professional connections.
  • Background checks should cross-verify information from multiple sources. For instance, check that verified addresses for the candidate match those where laptops are being sent.
  • For sensitive roles such as those who will have access to your electronic systems backend, add post-hire safeguards.
  • Require new hires to meet their supervisors and/or HR in-person, and where permitted by law, use geolocation verification and required check-ins for remote workers to confirm that they are working from where they say they are.
  • Train your internal recruiters to spot “red flags” in job candidates interviewing by video to identify and respond to such tactics, including such things as audio and video not syncing at the same time, seemingly scripted answers, refusal to perform real-time gestures such as looking up and looking down while on camera, and then escalate your concerns to security, legal, and compliance.
  • Call employment counsel immediately if a candidate fails identity checks, you plan to withdraw a conditional offer, you see indicators of a sanctions nexus, or any adverse action you plan to take that relies on biometric or identity-proofing results.

The takeaway for employers is clear: the combination of remote-first recruiting, outsourced screening and generative AI tools has created a new class of insider threat… someone you never actually intended to hire.

If you have any questions or seek legal advice on mitigating legal and operational risk with these kinds of issues, please contact Lisa Brauner in Whiteford’s Labor and Employment Law Department, Lbrauner@whitefordlaw.com, 646-618-8655, or any member of Whiteford’s Labor & Employment Law team.
The information contained here is not intended to provide legal advice or opinion and should not be acted upon without consulting an attorney. Counsel should not be selected based on advertising materials, and we recommend that you conduct further investigation when seeking legal representation.