How to verify a remote developer's identity when the interview is compromised
Proxy candidates, deepfake video and live audio coaching are routine in remote technical interviews. Here is the verification process that works.

Table of contents
A remote video interview is no longer enough to prove that the person on screen is the person who will do the work. A candidate can use a proxy, a live face swap, an earpiece or other AI tools to make a compromised interview look convincing. Greenhouse reports that 86% of recruiters had caught or suspected candidate fraud in the previous 12 months, while 36% of jobseekers reported changing their appearance, background or voice during video interviews.
You do not need to buy a proctoring system to reduce that risk. The stronger approach is to use several checks that are difficult to fake consistently:
Give the candidate an unscripted physical task on camera.
Supervise a short re test of any take home assessment.
Make contact across more than one session rather than relying on a single interview.
Take at least one reference from a source you found yourself.
These checks do not make fraud impossible. They make it harder to maintain a false identity across different situations and give you more evidence than a single video call can provide. Research on remote assessments also shows why relying on an unsupervised test alone is risky: a meta analysis covering 109 effect sizes from 49 studies found higher scores in unproctored assessments, with the difference smaller for tasks that are difficult to research online.
There is one important gap in the evidence. Nobody publishes a reliable figure for how many remote developer candidates actually commit identity or proxy fraud. The process therefore has to work without assuming a particular fraud rate. The question is not how many candidates are cheating. It is whether your hiring process can still establish who someone is and what they can actually do when the interview itself can be manipulated.
Key Facts
| Figure | Source |
|---|---|
| 86% of recruiters had caught or suspected candidate fraud in the past 12 months | Greenhouse 2026, n=198 recruiters |
| 36% of candidates have modified their appearance, background or voice on video | Greenhouse 2026, n=1,700 jobseekers |
| No significant effect for anti-cheating countermeasures, across 109 effect sizes from 49 studies | Steger, Schroeders and Gnambs, EJPA |
| How many remote developer candidates actually commit identity or proxy fraud | Not published. Nobody measures it |
In this article
How common is fraud in remote technical hiring?
How does interview fraud actually work, mechanically?
What does detection software catch, and what does it miss?
What verification steps work without buying a tool?
How do you build this into a repeatable hiring process?
WHat RocketDevs does instead
Conclusion
FAQ
How common is fraud in remote technical hiring?
Nobody knows, and the figures in circulation do not answer the question. The strongest available measurement is a perception measure. In Greenhouse’s 2026 AI in Hiring Report, 86% of the 198 recruiters surveyed across the UK, Ireland and Germany said they had caught or suspected candidate fraud in the previous 12 months. Greenhouse 2026 AI in Hiring Report
That is a percentage of recruiters, not candidates. The closest behavioural measure comes from the other side of the same survey. Of 1,700 jobseekers, 36% said they had modified their appearance, background or voice during a video interview, while another 21% said they would consider doing so. However, the category includes ordinary changes such as using a virtual background, so it cannot be treated as a deepfake or identity fraud rate. Greenhouse also sells candidate fraud filtering software, which is relevant context when assessing these figures.
Several other numbers are frequently quoted as evidence of widespread interview cheating, but they do not withstand closer examination.
“38.5% of candidates are cheating” comes from Fabric, an AI interview vendor. Its figure refers to 38.5% of 19,368 interviews on its own platform that its own detector flagged above a 40% probability threshold. That measures the output of a commercial detector on a self selected pool, not the prevalence of fraud among remote developers.
“81% of Big Tech interviewers” and “96% of hiring professionals” have no originating study that we could locate.
“61% of companies use detection software” is attributed to Greenhouse, but the edition of the report we could verify gives 59% and limits the figure to the UK, Ireland and Germany.
The distinction matters. A recruiter suspecting fraud, a candidate changing a virtual background, and software flagging an interview are three different measurements. None tells us what percentage of remote technical candidates actually use a false identity, a proxy or other assistance to pass an interview.
So the defensible conclusion is simple: the prevalence of identity and proxy fraud in remote technical hiring is unmeasured.
That does not make the problem impossible to address. The evidence below focuses on a different question: which verification methods make these attacks harder to sustain? That question can be tested without knowing how many candidates are attempting to cheat in the first place.
How does interview fraud actually work, mechanically?
A remote technical interview has three separate attack surfaces, and defeating one does not defeat the other two:
Audio assistance: someone or something feeds answers to the real candidate in real time.
Video manipulation: the candidate’s face or voice is altered during the call.
Identity substitution: a different person takes the interview and may later do the work.
Greenhouse’s 2026 survey found evidence of all three. Recruiters reported seeing candidates use AI during interviews (32%), candidates appearing to be in a different time zone from the one they had stated (28%), and a different person appearing for the interview than the person who applied (25%).
1. Audio assistance
This is the cheapest attack because it can leave no visible trace. A second screen, phone or earpiece can provide answers while the genuine applicant remains on camera. The person being interviewed really is the applicant, but they are not necessarily producing the answers themselves.
IEEE Spectrum’s reporting on the technical interview arms race describes the mechanism directly: an answer can be delivered to the candidate in real time, leaving them to perform as though they already knew it. IEEE Spectrum: The Technical Interview AI Arms Race
Nothing you do to the video feed can reliably detect this. The camera can show exactly what you expect to see while the useful information is arriving through another channel.
2. Video manipulation
Deepfake video is a more technically demanding attack, and it has a documented weakness. In GOTCHA, a study accepted to IEEE Euro S&P 2024, researchers at NYU Tandon evaluated real time deepfake systems across 56,247 videos involving 47 participants. They found that these systems generate frames independently or with dependencies on only a limited number of previous frames, generally no more than 10, to maintain real time performance. GOTCHA: Real Time Deepfake Detection
That creates a weakness when the face is forced to do something unusual. The researchers found that structured light, occlusion and facial deformation could degrade the generated output, with occlusion having the strongest effect.
The FBI’s Internet Crime Complaint Center identified a related problem in its 2022 warning about deepfake job candidates, noting that the person’s actions and lip movements may fail to coordinate completely with the audio. FBI IC3 Public Service Announcement
The implication is practical: a system optimised to reproduce a face during an ordinary conversation may struggle when that face is deliberately obstructed, moved or asked to perform something unexpected.
3. Identity substitution
The third attack is different because there may be nothing technically wrong with the video. The person on camera is a real human being, and they may be perfectly capable of doing the job. They are simply not the person who applied.
That makes identity substitution particularly difficult to detect with a conventional interview. A convincing video call can establish that someone is real without establishing that they are the right person.
The problem is not theoretical. In November 2025, Cybersecurity Dive reported on U.S. prosecutions involving North Korean remote workers and facilitators. The cases involved more than 136 U.S. companies and the compromise of more than a dozen Americans’ identities, with company laptops kept at U.S. addresses to make the workers appear to be where they claimed to be. Cybersecurity Dive: DOJ North Korea Remote Worker Crackdown
These are three different attacks with three different costs and three different weaknesses. Audio assistance can leave the video untouched. Video manipulation can leave the person’s underlying identity unchanged. Identity substitution can produce a perfectly normal looking interview.
A hiring process designed to verify only what appears on screen is therefore checking just one part of the problem.
What does detection software catch, and what does it miss?
Most teams already use some form of detection software, but the technology has not settled the underlying problem. In the Greenhouse survey, 59% of hiring managers said they use software to detect or monitor AI use during interviews at least some of the time. Among those who do not, 74% said they are considering it.
The evidence on whether that investment solves cheating is less reassuring. A meta analysis covering 109 effect sizes from 49 studies compared proctored and unproctored ability tests. In co author Ulrich Schroeders’ summary, the researchers found no significant overall effect from implementing anti cheating countermeasures. Ulrich Schroeders: Proctored vs Unproctored Testing Meta Analysis
Detection can also create a second problem: false positives. Archie Payne, quoted by IEEE Spectrum in its reporting on the technical interview arms race, noted that strong candidates have sometimes been flagged incorrectly. That means a detection system can create a cost in the opposite direction, rejecting a legitimate candidate because the software is uncertain.
The research itself also has a major limitation. A May 2026 preprint from the Vector Institute examined 389 deepfake detection papers published between 2017 and 2025. It found that 71.0% focused on face manipulation involving public figures, while none addressed real time detection. Vector Institute: Deepfake Detection Research Review
That matters because remote hiring is a real time problem. A detector trained and evaluated on previously recorded deepfakes is not necessarily capable of identifying a manipulation occurring during a live technical interview.
The federal identity standard in the United States reflects this distinction. NIST Special Publication 800 63A requires identity proofing providers to examine submitted digital media for signs of modification, manipulation, tampering or forgery. It recommends analysing media for generative AI signatures, but does not make that a requirement. NIST Special Publication 800 63A
The lesson is not that detection software is useless. It can provide another signal. The problem is treating that signal as proof.
A detector can tell you that something looks suspicious. It cannot, by itself, establish that the person on screen is the applicant, that the applicant produced the answers, or that the person who interviewed is the person who will actually do the work.
What verification steps work without buying a tool?
The most useful checks do not try to detect every possible form of cheating. They make the attack harder to execute or harder to sustain.
The principle is simple: force the deception to operate outside the conditions it was designed for, then verify the candidate again later.
| Attack vector | What the attacker needs | What you can do | Cost to you | How often it happens |
|---|---|---|---|---|
| Live audio coaching | A second device and a plausible way to receive answers | Ask unexpected follow ups about the candidate’s own answer and change the problem slightly | None. This is part of a normal technical interview | Not published |
| Real time face swap | Real time processing and enough bandwidth to maintain the video | Use an unscripted physical action, such as briefly covering the face or making a sharp head movement | About 30 seconds | Not published |
| Proxy candidate | A second person capable of passing the interview | Spread contact across several sessions and take a reference from a source you found yourself | Two extra calls and one phone call | Not published |
| Unproctored take home | Time, tools and potentially outside assistance | Run a short supervised re test using the candidate’s submitted work | 20 to 30 minutes per finalist | Not published |
The last column is deliberately left blank. None of the sources that meet this article’s evidence standard publishes a reliable prevalence rate for these individual attack methods. Vendor estimates should not be turned into industry wide statistics simply because they are the only numbers available.
- Make the interview harder to script
A live audio coach works best when the candidate can anticipate the questions and relay the answers. Unexpected follow ups make that harder. Ask the candidate to explain why they chose a particular approach, change one requirement, or diagnose a new failure in the solution they just proposed.
The goal is not to catch someone with a trick. It is to see whether they can reason through their own answer when the conversation moves somewhere they could not have prepared for.
- Stress the video channel
Real time face manipulation has a technical constraint: systems have to generate convincing output quickly enough to maintain a live conversation. Research presented at IEEE Euro S&P 2024 found that some real time deepfake systems rely on a limited number of previous frames to maintain throughput. The researchers also found that occlusion and facial deformation could degrade the generated output. GOTCHA: Real Time Deepfake Detection
That makes an unscripted action more useful than a scripted request. Briefly asking someone to move their head sharply, place a hand near their face or otherwise change the normal visual pattern introduces something the system cannot anticipate from a prepared sequence.
It is not a guaranteed deepfake detector. It is a low cost way of adding a condition that some real time manipulation systems find difficult.
- Verify the person across time
A proxy candidate can defeat an excellent technical interview because the interview may be perfectly genuine. The problem is simply that the person answering the questions is not the person who will ultimately perform the work.
The simplest defence is to avoid making identity verification a single event. Use more than one live interaction, vary the format, and obtain at least one reference from a contact you sourced independently.
The attacker then has to maintain the same story, identity and capability across multiple points of contact rather than preparing one convincing performance.
- Re test the take home
An unproctored take home removes almost every synchronous signal at once. You cannot see who completed it, what assistance they received, or whether the submitted work represents their own unaided ability. A short supervised re test puts that signal back.
In a personnel selection study involving 954 candidates, Aguado and colleagues used a brief proctored verification test after an unproctored online assessment. The procedure identified approximately 13.84% of applicants as suspected cheaters. The researchers also found that the flagged candidates spent substantially more time than expected on the verification stage, with an average difference of 5.78 seconds per item.
The practical lesson is more important than the percentage: you do not need to supervise the entire assessment if you can independently verify the work afterwards.
Give the finalist 20 to 30 minutes to explain, modify or reproduce part of the work they already submitted. Ask them to make a small change, diagnose a deliberate bug, or explain a design decision. Someone who genuinely produced the original work should be able to engage with it again.
These checks are not substitutes for evaluating technical ability. They solve a narrower problem: establishing that the person you interviewed is the person who can actually perform the work. That is separate from judging developers when you cannot read the code yourself or assessing how candidates use AI assisted coding during an interview. RocketDevs: How to Evaluate Developers Without Technical Knowledge RocketDevs: How to Evaluate AI Assisted Code
How do you build this into a repeatable hiring process?
The process does not need another software layer. It needs a sequence that moves from checks that can be automated to checks that require the candidate to respond in real time.
That is broadly consistent with the structure of NIST’s identity proofing standard. NIST distinguishes remote unattended proofing, which is completely automated, from remote attended proofing conducted through a secure video session. Its requirements also include random human in the loop cues during capture. NIST Special Publication 800 63A
For a remote developer, the sequence can be simple:
Check the document trail before the first call.Verify the candidate’s identity documentation and obtain at least one reference from a source you found independently.
Run one unscripted challenge on camera.Ask for a simple physical action that varies from interview to interview. The point is not to catch someone with a trick. It is to introduce an unpredictable condition that is difficult to prepare for.
Interrogate their own answer, not a new question.Ask why they chose an approach, change one requirement or introduce a small failure into the solution they just described. Coaching can supply answers to predictable questions. It is harder to supply a coherent chain of reasoning about an answer the candidate has just produced.
Re test any take home under supervision.Spend 20 to 30 minutes asking the finalist to reproduce, explain or modify part of the work they submitted. You are testing whether the submitted work is connected to the candidate's actual ability.
Spread contact across sessions and days.Do not make identity verification a single event. Consistency across multiple calls and formats is more difficult to maintain than one convincing performance.
The order matters. Automated or documentary checks establish the basic identity trail first. The later steps introduce conditions that require a real person to respond in real time and demonstrate continuity across the hiring process.
Two rules make the process more resistant to preparation.
Rotate the on camera challenge
A fixed script eventually becomes another test that candidates can prepare for. The research on real time face manipulation supports using unexpected conditions because some systems struggle when the visual input changes in ways they were not designed to handle. GOTCHA: Real Time Deepfake Detection
Source at least one reference yourself.
Do not rely exclusively on contact details supplied by the candidate. Greenhouse reported that fake references were the most commonly reported form of candidate fraud in its survey, at 51%.
The process is deliberately low tech. Its strength comes from making identity consistent across documents, live behaviour, technical work, references and time rather than asking one detection system to decide whether a candidate is genuine.
What RocketDevs does instead
The verification process described above is a manual version of what a pre vetting model can do structurally. Instead of asking every founder to build these checks into every hire, RocketDevs puts 6 to 8 hours of human vetting into each developer and accepts roughly the top 2% of applicants. Its current site says that the process includes:
experience verification;
reference checks;
resume and portfolio review;
and multiple assessment stages.
That matters for identity as well as technical ability. A single interview gives a candidate one opportunity to present a convincing story. A multi stage process creates several opportunities to check whether the person, their experience and their technical ability remain consistent.
RocketDevs also publishes the basic terms rather than hiding them behind a sales call. The Associate tier starts at $9.99 per hour, and every hire comes with a 14 day risk free trial. The current pricing page states that the trial can result in a rematch or a full refund if the developer is not the right fit.
The pre vetting process is documented in more detail by RocketDevs, including coding assessment, project assessment, communication assessment and cultural alignment checks.
If you would rather not build the verification process yourself, you can start with a pre vetted developer pool. See RocketDevs pricing Before deciding, it is worth understanding exactly what pre vetting removes from your own hiring process. Read how RocketDevs pre vets developers
Conclusion
Remote hiring has created a verification problem that a video interview was never designed to solve. A real candidate can receive answers through an earpiece. A convincing face can be generated in real time. A genuine person can sit in front of the camera while someone else eventually does the job. A clean interview therefore proves less than it appears to prove.
The evidence also does not tell us how common these attacks are. Recruiter suspicion is not candidate prevalence, detector flags are not confirmed fraud, and vendor estimates cannot be treated as industry wide measurements. That gap is important, but it does not stop you from building a stronger process.
The practical answer is to verify the candidate in more than one way:
Check the identity and document trail before the first interview.
Introduce an unscripted human challenge during a live session.
Follow up on the candidate's own reasoning rather than asking only predictable questions.
Re test take home work under supervision.
Spread contact across multiple sessions and days.
Source at least one reference independently.
The goal is not to create a perfect anti fraud system. It is to make one convincing performance insufficient. NIST's current identity proofing guidance similarly uses supervised human interaction and random human in the loop cues because automated checks alone cannot establish trust in every remote interaction.
For a founder hiring one developer, this can be done in minutes rather than through another software subscription. For a company hiring repeatedly, the same principle can be built into a structured vetting process before a candidate ever reaches the client.
You do not need to know how many candidates are cheating to make cheating harder. You need a hiring process that asks the candidate to prove the same identity, ability and experience more than once.
FAQ
- How common is cheating in remote technical interviews?
No independent organisation publishes a verified prevalence rate. The best available measure is recruiter perception: 86% of recruiters in Greenhouse’s 2026 survey said they had caught or suspected candidate fraud in the previous 12 months. The widely quoted prevalence percentages we reviewed generally trace back to vendors measuring activity through their own products, so they should not be treated as industry wide fraud rates.
- Can you tell if a candidate is using a deepfake on video?
Sometimes, but there is no reliable visual test that catches every deepfake. Research on real time deepfake systems found that some pipelines process frames independently or rely on only a limited number of previous frames, which can make unusual movement, occlusion and other unexpected visual conditions more difficult to reproduce convincingly. GOTCHA: Real Time Deepfake Detection
The FBI has also warned about inconsistencies between a person's lip movements and the accompanying audio as a possible deepfake indicator. FBI Internet Crime Complaint Center
The practical answer is not to rely on spotting a deepfake by eye. Add an unscripted physical or conversational challenge that gives a manipulated video less opportunity to remain convincing.
- Are take home assessments safer than live interviews?
No. They can be more exposed because an unproctored take home removes the synchronous signals you get from a live interaction. You cannot directly observe who completed the work or what assistance they received.
A short supervised re test is a stronger way to verify the result. In a study of 954 applicants in a real personnel selection setting, researchers followed an unproctored online test with a proctored verification test and identified approximately 13.84% of applicants as suspected cheaters. Aguado et al.: Cheating on an Unproctored Internet Test
- What is proxy interviewing?
Proxy interviewing is when someone other than the applicant sits the technical interview. You may therefore assess a real person with genuine technical ability, but that person is not the one who will ultimately do the work.
In Greenhouse’s 2026 survey, 25% of recruiters reported seeing a different person interviewed from the person who applied. Proxy interviewing can survive conventional video checks because the person on camera is genuine. The problem is the identity behind the camera, not the authenticity of the video.
- Do you need proctoring software to hire remotely?
No. Software can provide another signal, but it does not solve every identity or assistance problem. Greenhouse reported that 59% of hiring managers use software to detect or monitor AI use during interviews at least some of the time. Meanwhile, a meta analysis covering 109 effect sizes from 49 studies found no significant overall effect from anti cheating countermeasures in the proctored versus unproctored testing literature. Ulrich Schroeders: Proctored vs Unproctored Testing Meta Analysis
NIST's identity proofing standard requires analysis of digital media for signs of manipulation and forgery, but its approach also includes human involvement in remote attended proofing. Automated analysis is one layer of verification, not a substitute for establishing that the person on screen is the person you intend to hire. NIST Special Publication 800 63A
- How can a startup make remote hiring harder to fake?
Start with a structured hiring process rather than adding a detection tool at the end. RocketDevs: How to Hire Developers for a Startup Use a consistent technical question framework, then add identity checks that are difficult to prepare for: an unscripted live challenge, follow ups on the candidate's own reasoning, a supervised re test of take home work, and a reference you sourced independently. RocketDevs: Front End Developer Interview Questions and Answers
The aim is not to catch every possible form of cheating. It is to make one convincing interview insufficient evidence of identity and ability.
Sources
Greenhouse, The 2026 AI in Hiring Report, UK, Ireland and Germany edition, surveying 1,700 jobseekers, 198 recruiters and 373 hiring managers. Greenhouse sells a candidate fraud-filtering product. Fielding dates and research partner are not disclosed in the report.
Govind Mittal, Chinmay Hegde and Nasir Memon, NYU Tandon, GOTCHA: Real-Time Video Deepfake Detection via Challenge-Response, accepted to IEEE Euro S and P 2024, 56,247 videos from 47 participants
Aguado, Vidal, Olea, Ponsoda, Barrada and Abad, Cheating on Unproctored Internet Test Applications, The Spanish Journal of Psychology, 2018, n=954
Steger, Schroeders and Gnambs, A Meta-Analysis of Test Scores in Proctored and Unproctored Ability Assessments, European Journal of Psychological Assessment, summarised by Ulrich Schroeders, University of Kassel
NIST, Special Publication 800-63A, Identity Proofing and Enrollment, sections 2.1.3, 3.11 and 3.14
FBI Internet Crime Complaint Center, Alert I-062822-PSA, Deepfakes and Stolen PII Utilized to Apply for Remote Work Positions, 28 June 2022
Eric Geller, US chips away at North Korean IT worker fraud, Cybersecurity Dive, 17 November 2025
Rina Diane Caballar, AI in Hiring Turns Technical Interviews into Arms Race, IEEE Spectrum, 13 July 2026
Shaina Raza, Vector Institute, The Deepfakes We Missed, arXiv:2605.12075, 12 May 2026
Fabric, State of AI interview cheating in 2026, cited only as an example of a figure that cannot be read as a prevalence rate
Three figures you will meet elsewhere that are missing here on purpose. Gartner's candidate-fraud survey is the most useful number in this category and it sits behind a paywall, so it is not quoted above. The Steger meta-analysis is paywalled at the publisher too, so only the findings readable at an open source appear here and the effect size is left out. And the widely repeated "81% of Big Tech interviewers" and "96% of hiring pros" claims trace back to no locatable study, so they are absent rather than softened. If a vendor quotes you any of the three, ask them for the primary source.

Written by
James Hitch
COO
James Hitch is the COO of RocketDevs, where he runs sales, recruiting, and the vetting operation that accepts only the top 2–3% of developer applicants. He cares about putting accessible, elite engineering talent within reach of founders and startups worldwide, at a fair price. He writes about technical hiring, building AI-native engineering teams, and how startups can access elite developers affordably.
More from our blog
Continue exploring insights and stories from RocketDevs
