All posts
4 August 2026· 3 min read

The Interview That Wasn't: Deepfakes and the New Hiring Attack Surface

North Korean operatives are passing live video interviews with real-time deepfake filters. Every company that hires remotely now needs a way to tell a candidate from a projection.

A hiring manager at a crypto startup runs a second-round interview over video. The candidate answers cleanly, references match, the portfolio looks real. He gets hired. Weeks later, the company finds out he was never a person at all, or rather, not the person on screen. A North Korean operative wore his face.

This is the tactic CrowdStrike attributes to the group it calls Famous Chollima: steal a real engineer's identity and résumé, then run a real-time AI filter over a live video call to wear that stolen face during the interview. Voice modulation tools mask the accent on phone screens. The goal isn't the job itself. It's the access: source code, credentials, and a foothold to extort the company from once discovered. CrowdStrike's 2026 Technology Threat Landscape Report found this single group behind 47 percent of all state-sponsored hands-on intrusions against US tech companies in the year to March 2026.

Job interviews used to be one of the few places a company could reliably put a human in front of a human. That assumption is gone. The same real-time deepfake tooling that fooled hiring managers is now aimed at the automated side of onboarding too: know-your-customer checks, liveness prompts, document verification, all built to catch a static photo, not a face that blinks, turns, and answers questions on command.

The exposure is worst where verification volume is highest and scrutiny is thinnest, exactly the developer-outsourcing markets, Türkiye, India, Pakistan, that drive much of frontier AI platform usage and remote hiring alike. Western-trained detectors are calibrated on Western faces and Western lighting. They miss what they were never shown.

Fixing this isn't a matter of hiring more reviewers or adding another verification step to slow everyone down further. It's a matter of what the detection model has seen. A detector that has only ever been trained on real employee photos and real fraud attempts has a training set as small as the fraud it's caught so far, which is to say, too small. Fraud tactics move faster than any single company's incident log.

Synthetic data closes that gap before the gap gets exploited. Instead of waiting for the next Famous Chollima technique to show up in a security bulletin, a detector can be hardened against realistic, demographically calibrated synthetic identities running the same face-swap and liveness-evasion techniques, at populations and volumes no real fraud case would ever generate on its own. That's the difference between a detector that reacts to last year's attack and one that's already seen next year's.

TessLabs builds that training data: mathematically locked synthetic identities, reproducible across the exact edge cases a detector fails on, calibrated for the populations existing detectors miss. If your onboarding or hiring pipeline still assumes the face on the call is the face on the résumé, it's worth checking what it would take to prove that.

Read the white paper or book a call to see the detection benchmarks.

FAQ

How do North Korean IT workers use deepfakes to pass job interviews?
Operatives steal a real engineer's stolen identity and résumé, then run a real-time AI face filter over a live video call to wear that person's face during the interview. Voice modulation tools mask the accent on phone screens, letting the same operative pass as multiple different candidates.

What do North Korean fake IT workers want once they're hired?
Access, not the salary. Once inside, operatives steal source code and credentials, and extort the employer by threatening to leak proprietary code if discovered. CrowdStrike attributes 47 percent of all state-sponsored hands-on intrusions against US tech companies in the year to March 2026 to this single group.

Can standard video interviews or KYC checks catch a real-time deepfake?
Not reliably. Most liveness and onboarding checks were built to catch a static photo, not a face that blinks, turns, and answers questions on command in real time. Detection has to be trained specifically against real-time face-swap and voice-modulation techniques, calibrated for the populations the attacks actually target.

Case study: CrowdStrike's 2026 Technology Threat Landscape Report, via Tech Times and DarkReading.

Measuring this on your own model

The first step is a sample built to your specification, which you score on your own detectors and benchmarks. No cost and no commitment.