Why Your Next Applicant Might Be Fake and the Rise of Synthetic Job Applicants
- 5 days ago
- 6 min read
Christopher Smith is an award-winning author and entrepreneur dedicated to protecting people from cybercrime. After being the target of a major cyberattack, he founded DFend, a digital safety platform, and wrote Privacy Pandemic, inspired by his real-life story.
Over the past six months, many of my conversations with friends and family about finding new work have circled back to the same worry. They apply for job after job, despite being well qualified, and hear nothing back or receive a rejection so quickly that they assume no human ever read their application.

Their frustration is real, even if the cause is often misunderstood. The popular belief that artificial intelligence automatically rejects most résumés before a person sees them is not always accurate. At many employers, a person is still involved at some stage of the process. But something is distorting the market.
In July 2026, the Texas Attorney General opened an investigation into LinkedIn over “ghost jobs,” listings that may not correspond to a real opening and which, by some estimates, account for one-fifth to one-third of online postings.
That is only one side of the problem. While real applicants chase jobs that may not exist, fake applicants are quietly being hired into jobs that do.
Companies have spent years protecting employee accounts after people are hired. Synthetic applicants expose an earlier vulnerability: an organization may not know who it is hiring in the first place.
What is a synthetic applicant?
Recruiting and cybersecurity have traditionally operated as separate functions.
Human resources evaluates a candidate. A screening provider checks selected credentials. Information technology issues a device. Cybersecurity begins monitoring after the employee receives access.
Synthetic applicants make that separation increasingly risky. An attacker can apply for a job, complete video interviews, pass identity checks, receive a company laptop, and enter an organization using legitimate credentials.
The applicant may be supported by stolen personal information, altered documents, fabricated employment histories, AI-generated photographs, voice-changing software, proxy internet infrastructure, and local facilitators.
The person performing the work may also be located in a different country from the one claimed. A company laptop can be shipped to an intermediary who installs remote access software, allowing an overseas operator to appear locally based.
Microsoft has documented threat actors using artificial intelligence to create tailored résumés, professional photographs, fake developer profiles, altered identity documents, and disguised voices.
AI is not creating the underlying fraud. It is making fraudulent applicants faster, cheaper, and more convincing. Although many of the best documented cases involve North Korean technology workers, the same methods could be used by criminal groups, commercial espionage operations, or individual fraudsters.
A UK bank reportedly faced more than 700 suspicious applications
In July 2026, The Times reported that more than 700 suspected North Korean applications were submitted for remote roles at a major UK bank.
The applications were reportedly flagged by an AI recruiting system that detected patterns across the candidate pool. Individual applications appeared credible, but their collective behavior revealed signs of coordination.
A company does not need to make 700 hiring mistakes. It needs to make one. One successful applicant could gain legitimate access to internal communications, customer information, financial systems, proprietary technology, or privileged infrastructure.
The UK's National Cyber Security Centre has also warned that British organizations are being targeted by North Korean technology workers posing as freelance professionals from other countries.
The recruiting process is no longer only a way to acquire talent. It is becoming part of the company's security perimeter.
How AI tools are filtering job applicants
The same technology that helps attackers construct synthetic candidates can also help employers identify them.
A recruiter reviewing one application may not notice repeated language, unusual application timing, location inconsistencies, shared technical or network signals, or coordinated behavior across hundreds of candidates. AI systems can analyze applicants collectively and identify patterns that would be difficult for an individual reviewer to see. Automated filtering also creates risks.
Algorithms can generate false positives, reinforce existing bias, rely on signals that candidates cannot examine, and reject qualified applicants who have little opportunity to challenge the decision. Someone using a virtual private network, working temporarily abroad, or relying on assistive technology may produce unusual signals for entirely legitimate reasons. The appropriate model is AI-supported investigation, not automatic rejection.
AI can identify anomalies and coordinated activity. Trained employees should evaluate the evidence, apply proportionate controls, and give candidates a meaningful opportunity to verify their identities or correct errors.
Fraudulent workers obtained jobs at more than 300 US companies
The United States shows what can happen when fraudulent applicants make it through the hiring process.
In one Justice Department case, an Arizona woman helped North Korean workers pose as US citizens and residents to obtain remote positions at more than 300 American companies.
The operation used stolen identities and a domestic “laptop farm” that allowed overseas workers to access employer-issued computers while appearing to work inside the United States. The scheme generated more than $17 million in illicit revenue.
A separate Justice Department case alleged that North Korean workers, supported by facilitators across several countries, obtained employment at more than 100 US companies.
The FBI has warned that some North Korean technology workers copied sensitive company data and used stolen proprietary data for extortion.
This is not simply résumé fraud. It can create exposure across cybersecurity, sanctions compliance, intellectual property, payroll, privacy, and national security.
The model is expanding across Europe
Google Threat Intelligence Group has documented increased North Korean remote worker activity across Europe.
Investigators observed workers using multiple identities, fabricated references, virtualized corporate infrastructure, and bring-your-own-device arrangements that created fewer conventional evidence trails.
The vulnerability is built into the structure of global remote work.
Companies recruit internationally, interview by video, verify documents online, ship devices remotely, and provide access through cloud platforms. Those systems make global hiring possible, but they can also be manipulated.
How companies should respond
In my view, the answer is not to abandon remote hiring or treat international applicants as inherently suspicious. Organizations should connect recruiting, identity verification, cybersecurity, compliance, legal, and access management.
Before an interview, employers can validate credentials, confirm employment histories, and examine application patterns for signs of coordinated activity. Before granting access, they can use proportionate identity and liveness checks, confirm work locations, validate devices, and restrict unauthorized remote access tools.
After hiring, they can apply least privilege access, monitor unusual network behavior, and periodically reverify people working in sensitive roles. This is not a case for permanent employee surveillance. It is a case for better verification when someone receives access to valuable systems, data, money, or intellectual property.
Every company hiring remotely should ask one question: Who is responsible for confirming that a candidate is who they claim to be?
If recruiting, cybersecurity, compliance, and access management cannot answer that question together, the organization may already have a serious security gap.
Leaders should review their remote hiring controls now, before the next synthetic applicant becomes a trusted insider.
Read more from Christopher A. Smith
Christopher A. Smith, Author & Digital Safety Advocate
Christopher Smith is the award-winning author of Privacy Pandemic and the founder of DFend, a digital safety platform built to protect people from cybercrime. After being the target of a major cyberattack, he transformed his story of loss into one of purpose, turning a personal crisis into a global mission. His experience inspired him to develop technology that helps individuals safeguard their identity and privacy in the age of AI. Through his work and writing, Chris advocates for greater awareness, protection, and resilience online. He believes the future of digital safety is personal, because the threat already is.
References:
Office of the Texas Attorney General: Investigation into LinkedIn Over “Ghost Jobs”
Microsoft Security Blog: AI as Tradecraft: How Threat Actors Operationalize AI
Google Threat Intelligence Group: Staying a Step Ahead: Mitigating the DPRK IT Worker Threat
US Department of Justice: Arizona Woman Sentenced in $17M IT Worker Fraud Scheme
US Department of Justice: Coordinated Nationwide Actions to Combat North Korean Remote IT Worker Schemes
Federal Bureau of Investigation: North Korean IT Workers Conducting Data Extortion
Disclaimer:
The views, opinions, observations, and interpretations expressed in this article are solely those of the author at the date of publication. They may or may not be based on personal experience, publicly available information, and the author's analysis of industry developments.
References to companies, technologies, products, markets, or historical events are provided for informational and educational purposes only. Any conclusions, forecasts, or interpretations represent the author's opinions and should not be construed as statements of fact, investment advice, legal advice, financial advice, or professional advice of any kind.
The views expressed do not necessarily reflect the views of any current or former employer, client, partner, advisor, board, organization, or affiliated entity. Past outcomes, experiences, and observations discussed herein should not be interpreted as guarantees of future results. Market conditions, timing, execution, capital availability, competitive dynamics, regulatory developments, and other factors may materially affect outcomes.
Readers should independently evaluate any information presented and consult qualified professionals regarding legal, financial, investment, tax, or other professional matters.










