A cinematic dusk portrait of a woman in profile with a second, slightly ghosted version of her own face offset behind her — one real, one not quite right.
    Recruitment

    Hiring in the Age of Deepfakes: The Story So Far

    A backend engineering role, a candidate who looked practically perfect, and a handful of small things that did not add up. The story behind our new series on deepfake hiring risk.

    July 15, 20266 min read·Samantha Swift, CMO at Cyberr
    All articles

    We posted a backend engineering role on LinkedIn and more than 100 people applied.

    That part was not unusual. Hiring for technical roles is noisy at the best of times, and anyone who has been near a recruitment process recently knows the ritual: lots of CVs, a handful of possible matches, a few people who clearly did not read the advert, and occasionally someone who looks practically perfect for the role.

    This was one of those.

    The candidate's CV matched the job. His experience looked relevant. The skills lined up. His profile looked credible. He had even sent a direct message to our CEO, which, at first glance, felt proactive rather than odd.

    On paper, they looked like exactly the kind of candidate you hope to find when you are hiring for a complex technical role.

    Then the small things started to stack up.

    Small things that stacked up

    The video and audio were slightly out of sync. Answers came a beat too late. The virtual background made it harder to see what was going on. Simple requests were dodged. Questions were met with questions. None of this, in isolation, would be enough to start waving a giant red flag around the room. Interviews are awkward. Video calls misbehave. People get nervous. Technology has a long and proud history of choosing the worst possible moment to become soup.

    Screenshot from the interview showing video and audio noticeably out of sync
    Screenshot from the interview showing video and audio noticeably out of sync

    But hiring, especially in cybersecurity, is rarely about one single signal.

    It is about patterns.

    And this pattern really did not feel right.

    That distinction matters, because the last thing hiring teams need is a culture where every awkward answer becomes suspicious and every candidate is treated like a threat. People are allowed to be nervous. People are allowed to have bad Wi-Fi. People are allowed to have a slightly strange interview style because, frankly, interviews are a deeply unnatural human activity.

    The issue here was different.

    Hiring is an access decision

    This was a candidate applying for a role where trust would matter. If hired, they could eventually have been given access to internal systems, source code, customer environments, tools, data, and the kind of context most organisations work very hard to protect.

    In cybersecurity, a hiring decision can become an access decision very quickly.

    That means trust does not begin with onboarding. It begins much earlier, with the claims someone makes when they enter the process.

    Who are they? Where are they based? What have they worked on? Which skills can they actually demonstrate? Which parts of their background can be checked?

    As the process continued, the story became harder to believe.

    The Romanian check

    The candidate's CV listed Romanian as a spoken language. He also claimed to be a native Romanian based in Bucharest. So the interviewer asked whether they could continue the conversation in Romanian.

    That should have been a simple check.

    It was not.

    Screenshot from the interview showing the candidate, who claimed to be a native Romanian, refusing to speak Romanian
    Screenshot from the interview showing the candidate, who claimed to be a native Romanian, refusing to speak Romanian

    The candidate refused, and that refusal became a significant red flag. Not because candidates should be expected to perform tricks on demand, and not because language fluency should be used casually as a gotcha. It mattered because this was directly tied to the identity, location, and background the candidate had presented as part of the hiring process.

    Do you know what Cyberr does?

    Then came another simple question:

    Do you know what Cyberr does?

    Again, nobody expects a candidate to recite a website back word for word. That would be horrible. But if someone has applied for a role, messaged the CEO, and reached the interview stage, you would expect them to have a reasonable grasp of the company, the role, and why they are interested.

    The answer did not feel like that.

    Screenshot from the interview showing the first attempt, with the candidate hesitating and struggling to answer
    Screenshot from the interview showing the first attempt, with the candidate hesitating and struggling to answer

    It felt vague. Disconnected. More like someone trying to talk around the question than someone answering from a place of genuine interest or understanding.

    By this point, we were no longer looking at one odd moment. We were looking at a thread.

    And once you start pulling that thread, the neat little candidate story begins to come apart.

    Why this series exists

    That is the point of this series.

    Deepfake hiring risk does not always arrive as a dramatic sci-fi moment. It does not necessarily announce itself with a glitching face and a suspiciously robotic voice. Sometimes it looks like a polished CV, a credible profile, a decent interview, and a handful of details that are just plausible enough to keep the process moving.

    That is what makes it dangerous.

    AI-assisted applications, synthetic identities, fake credentials, manipulated profiles, and deepfake interviews are already part of the hiring landscape. For cybersecurity teams, the risk is sharper because the person you hire may be trusted with systems, information, and decisions that matter.

    This is not a call for paranoia. Paranoia is not a strategy, and it is a terrible hiring manager.

    It is a call for better signal.

    A polished CV is useful, but it is not proof. A confident interview can be helpful, but it is not proof. A credible-looking profile gives you context, but it is not proof. In critical hiring, especially where access and security are involved, teams need ways to verify the things that matter without turning the process into an obstacle course built by goblins with clipboards.

    That is part of why Cyberr exists.

    We are building a professional network for cybersecurity where trust signals matter. Identity verification, validated certifications, role context, and credible professional history should not be afterthoughts. They should help hiring teams make better decisions earlier, and help genuine cybersecurity professionals stand out for the right reasons.

    The series

    Our five-part series, Hiring in the Age of Deepfakes, walks through what happened in this real hiring process, what started to feel wrong, and how the team handled it as the story unravelled.

    • Episode one asks whether the perfect candidate really exists.
    • Episode two looks at the small things that felt off.
    • Episode three covers the Romanian language check.
    • Episode four shows what happened when the candidate was asked whether they knew what Cyberr does as a company.
    • Episode five brings the story together.

    We also have a practical guide coming soon for hiring teams who want to understand deepfake candidates, identity risk, and the checks that can help reduce exposure. That guide is not quite ready yet, but this story is too important to keep parked until then. I'll pen a new blog once the final episode is released, and the guide is available.

    For now, the lesson is simple enough:

    In critical hiring, verify early and verify often.

    Watch the series, and join Cyberr to see the final episode before anyone else.

    Join the cybersecurity community

    Create your free Cyberr account today.