Ghost candidates:
how AI-generated fraud is quietly filling your pipeline
 

Your next submission could be someone who isn’t real. Here's how to tell before it costs you.


Picture this: a candidate sails through your screening call, ticks every box on the CV, and then something doesn’t feel quite right. Was the video too smooth? Did their answer to a question come just a moment too fast? You find yourself shrugging it off and move them forward anyway, because you've got twelve more calls to get through today. 

But, now more than ever, it is worth trusting your gut. AI has made it cheap to fake a CV, an identity, even a live interview, and it's not some future risk sitting on a compliance roadmap somewhere. It's probably in your pipeline right now, at volume. Gartner expects one in four candidate profiles globally to be fake by 2028.

In a recent Greenhouse survey, 91% of hiring managers said they'd already encountered or suspected AI-generated interview answers. 
The same tools that write a flawless CV in seconds can now convincingly sit in for someone on camera. Which means the question isn’t whether a ghost candidate has been through your desk. It's whether you caught it. 


What does a ghost candidate actually cost?

Every hour you spend shortlisting, interviewing and reference-checking someone who never existed is an hour you didn't spend on a candidate you could have placed. Multiply that across a desk running twenty roles, and it soon shows up in your real time-to-hire slipping while you chase someone who was never going to show up on day one. 

Then there's the potential for exposure. If a fake identity gets through to placement, the compliance risk lands on the agency as much as the client. The US Department of Justice found over 130 companies had unknowingly hired North Korean IT workers using stolen or synthetic identities, funnelling millions in fraudulent salaries. Amazon alone blocked more than 1,800 suspected applicants tied to the scheme, with attempts climbing 27% quarter on quarter.  

Amazon has an entire security team built to catch this. Most recruitment and staffing companies don’t. If it’s already happening to a company with those resources, it’s worth asking yourself how confident you are that your own processes could catch it? 

And beyond the legal exposure, there's the client relationship. Placing someone who turns out not to be who they said they were is exactly the kind of failure that makes a client question whether they can trust your process at all. 


Catching it before it costs you

Here’s the good news: most of this fraud is not that clever. It relies on speed and volume, not sophistication. Slow down, tighten a few habits and you can catch the majority of it. A few consistent habits will do more here than any expensive new tool.  

Build these into every process, not just the ones where you suspect you have gaps: 

  • Insist on live, unobscured video for at least one interview stage. Deepfake tools still struggle with natural lighting changes, side profiles and unscripted questions.  
  • Watch for lip-sync mismatches and odd pauses when a candidate is asked something they couldn't have prepared for. 
  • Match delivery addresses for any equipment to the address on their ID. This single check has flagged a huge share of North Korean IT worker schemes. 
  • Cross-check employment dates and education history against what's actually verifiable, not just what's written down. 
  • Delay system access until background checks have cleared. Don't let onboarding speed outrun due diligence. 

This isn't just theory. Sebastian Paredes at Interlix Staffing posted about catching a deepfake live, mid-interview, using exactly this kind of scrutiny. If it can happen on his desk, it can happen on yours.

Where clean data comes in

All of this gets a lot easier if your data isn't a mess to begin with. A CV that doesn't quite match a previous submission, a phone number that keeps turning up against different names, a work history that shifts between applications are the fingerprints a ghost candidate leaves behind. But you'll only spot them if your Bullhorn records are accurate and deduplicated in the first place. Messy data doesn't just slow your desk down. It gives fraudulent candidates somewhere to hide. 

This is exactly the groundwork Kyloe DataTools is built for. Alongside merging duplicates and flagging inconsistent fields, its new Trust Score feature lets you independently score a candidate record against external verification checks, so you get a clear read on how accurate (and how real) a profile actually is, rather than relying on gut feel alone. 

And it's not just for your senior consultants to worry about. Fraud tends to target the fastest-moving, least scrutinised part of the pipeline, which in a lot of agencies is exactly where your newest recruiters are working. Get the whole team trained on this, and get the underlying data clean, and you've closed off the two easiest routes in. 

The real question isn't whether a ghost candidate has been through your pipeline already. 

It's whether your data would actually show you when it does.

 




Book a Bullhorn data health check with Kyloe and find out.



Read our Blog