A fake interview may aim to take your money, identity documents or device access. Verify the employer and role through independently obtained contact details before sharing sensitive information, paying or running software. A video call, a convincing face or a head-turn challenge cannot authenticate the job.
There are two different stories in reporting about deepfake interviews. One concerns criminals pretending to be recruiters. Another concerns fake applicants trying to enter an employer’s workforce. They require different defenses and should not be counted as the same threat.
The FBI’s warning about North Korean IT workers describes identity deception aimed at employers. It does not establish how frequently job seekers face an AI-generated hiring manager. The FBI separately documents criminal use of generative AI for convincing messages, identities and real-time impersonation. That supports caution about appearances, not a numerical claim about the interview in front of you.
Four things a fake interview may be selling you
—A job that does not exist. The recruiter borrows a real employer’s name or creates a company identity. The interview provides a reason to trust later instructions.
—A form disguised as onboarding. The objective may be your identity documents, tax details or banking information. Some genuine hiring processes need sensitive data, so the issue is the verified employer, purpose, timing and submission route—not a blanket rule that every request is fake.
—A payment disguised as preparation. You may be told to buy equipment from a named vendor or send money back after depositing a check. A bank making check funds available does not establish that the check is genuine.
—A download disguised as an assessment. A task, repository or video-call fix can be a route to malware. Technical applicants should assess what they are being asked to execute, not just whether the exercise looks relevant to the role.
The FTC’s job-scam guidance covers fake hiring and equipment-check schemes. For a concrete malware pattern, the FBI’s September 2024 alert describes recruitment pretexts aimed at people in cryptocurrency and related industries, including unknown code packages and supposed conferencing fixes. That alert has a specific industry focus; it is not evidence that every coding assessment is malicious.
The 12-point interview check
—1. Find the company yourself. Use its independently located website rather than the recruiter’s link. Check the exact domain, including lookalike spelling and subdomains.
—2. Confirm the role. Ask the company whether the position and recruiting agency are authorized. An absent public listing is a reason to ask; some genuine roles are not advertised publicly.
—3. Confirm the person. Contact recruiting or HR through the company’s own route. A profile, badge or email signature alone can be copied.
—4. Read the email address. Check the complete sender and reply-to addresses. A correct-looking address is useful but not sufficient, because accounts can be compromised.
—5. Compare the work with the pay. Ask for responsibilities, employment status, location and payment terms. Vague tasks and exceptional pay without assessment need explanation.
—6. Check every money request. Do not send money to release wages or return part of a recruiter’s check. Independently verify any legitimate certification or equipment expense before committing.
—7. Ask why personal data is needed now. Request the purpose, responsible organization and privacy information. Supply only necessary information through a verified route.
—8. Verify the upload portal. A real employer may use an outside hiring service. Confirm that specific service with the employer before uploading ID; do not assume either all external portals or all branded portals are safe.
—9. Inspect the assessment. Do not run unknown commands, install remote-access tools or disable security protections at a recruiter’s request. Independently confirm both the recruiter and the task.
—10. Keep work devices out of unverified tests. If an assessment requires code execution, follow your organization’s security policy and obtain appropriate technical review. Isolation reduces exposure; it is not a reason to trust unknown code.
—11. Treat video as supporting evidence. A real face can lie and a deepfake may look smooth. Ordinary poor lighting or bandwidth can also cause visual artifacts. Do not make a financial decision from a glitch test.
—12. Save and compare the written offer. Match its legal employer, duties, pay and contact details to what you independently verified. Pressure to bypass those checks matters more than polished presentation.
Why asking someone to turn their head is not enough
Visual challenges are attractive because they offer an immediate yes-or-no answer. But the answer you need is broader: does this person represent this employer, is this a real role, and is the requested action part of its hiring process? Even a completely authentic video cannot establish all three.
A better check moves outside the conversation. Independently contact the employer and identify the exact recruiter, job and request. Do not let the recruiter supply the person who “verifies” them. If you cannot establish the connection, pause sensitive actions while you check.
If you shared something or ran the test
—Money or a check: Contact the bank or payment provider promptly. If you deposited a check, explain that it may be fraudulent and do not send funds onward because they appear available.
—Passwords or codes: Use a trusted device to secure the affected account, review sessions and change reused passwords. Contact the provider if recovery details were changed.
—Identity documents: Record what was disclosed and follow your country’s identity-theft guidance. In the U.S., IdentityTheft.gov provides a recovery plan. Credit freezes can help protect against new-credit misuse but do not address every form of identity fraud.
—Suspicious software: Disconnect the affected device from the network and seek qualified help. If it is a work device, notify your security team promptly. Use a separate clean device for banking and account changes.
—The conversation itself: Save messages, profile links, the offer, domains and filenames. Report the account to the recruitment platform and the impersonated employer through a verified route.
Use our identity-theft guide for exposed documents and our payment-method guide for money already sent. If the supposed role involves ratings and deposits rather than an interview, the more relevant guide is task scams.
Questions readers ask
Does a video interview prove a job is real?
No. A scammer may use their own face, a stolen identity or manipulated media. Verify the role and recruiter through contact details obtained from the employer’s independently located website.
Can I reliably detect a deepfake by asking someone to turn their head?
No. Visual glitches may prompt further checking, but their absence is not authentication and ordinary connection problems can look suspicious. Do not base a money or identity-document decision on a visual challenge.
Is a request for ID before an offer always a scam?
No. Hiring and identity-check requirements vary. Before sharing sensitive documents, confirm the employer and role independently, ask why the information is needed at that stage, and verify the upload service and privacy information.
What if an interview asks me to install software?
First verify the employer and the exact assessment through an independent channel. Do not run unknown packages, scripts or a supposed video-call fix just because a recruiter asks. If you already ran suspicious software, disconnect the affected device from the network and seek technical help; use a clean device for account security.