Detect Deepfakesby Resemble AI
Deepfake case study · Video

Hiring Fraud: A CPO’s Experience Interviewing a Deep…

Nisos Chief People Officer Magen Gicinto details an incident where a North Korean operative used deepfake technology to pose as a job candidate during a…

Incident date
Jul 2026
Target
Nisos
Updated Jul 28, 2026 · 1 min read

Nisos Chief People Officer Magen Gicinto recently shared firsthand experience with a sophisticated hiring fraud attempt, where a suspected North Korean operative used deepfake technology to infiltrate the company's recruitment process. This incident underscores the growing trend of malicious actors leveraging synthetic identities to exploit traditional hiring practices.

What happened

The incident occurred during a standard recruitment campaign for an AI architect engineer position at Nisos. After progressing through the initial stages of the hiring process, the candidate participated in a remote video interview that triggered immediate security concerns. During the call, the individual appearing on screen did not match publicly available images associated with the candidate's online professional identity. Gicinto concluded that the organization was dealing with a synthetic identity generated using deepfake technology.

This case was not an isolated event; Gicinto noted that organizations are increasingly encountering thousands of suspicious applications linked to North Korean operatives. These actors utilize AI-generated resumes, recently created LinkedIn profiles, and fabricated work histories to gain access to companies. The primary motive often extends beyond payroll fraud, as successful infiltration can grant bad actors access to sensitive source code, intellectual property, customer data, and internal communications.

Following the incident, Gicinto emphasized that hiring teams must move beyond traditional trust-based verification. She highlighted several warning signs, including candidates who rely heavily on off-screen prompts during video calls, inconsistent photographs across platforms, or resumes that mirror job descriptions with suspicious precision. As deepfake technology becomes more accessible, Gicinto advocates for a shift in recruitment where validating digital identity becomes as fundamental as assessing professional qualifications. Preventing such compromises requires a collaborative, enterprise-wide approach involving HR, recruitment, and cybersecurity teams to ensure that identity verification is treated as a core component of organizational security.

Sources