Key Insights
The natural reaction to a story about a fraudulent hire is confidence: we would catch that. We run background checks. We do multiple interviews. We verify references.
But so did the organizations that got caught out. Everything looked good because everyone was following the process, but that process left gaps behind that allowed these bad actors to slip through. This threat is built to defeat standard screening.
Keep reading, and we’ll discuss exactly where a fraudulent hire clears each checkpoint, why that gap is structural rather than a screening failure, and what actually catches them. If you've ever assumed your vetting would flag an impostor, this is the part to read closely.
What These Attacks Look Like
This is happening to all types of companies, including KnowBe4. A candidate applied to one of their software engineering roles with a strong résumé, and HR ran four separate video interviews, confirming the person on camera matched the application photo. The background check, standard pre-hire screening, and references even came back clean.
An investigation later conducted with Mandiant and the FBI found the worker had used a real U.S. citizen's stolen identity, an AI-enhanced photo, and deepfake technology in the interviews, routing their connection through a VPN to appear domestic. Every gate opened, and each one opened correctly based on what it could see.
The Four Places the Process Assumes Good Faith
A hiring pipeline is a series of trust decisions. Abnormal AI’s threat intelligence team has mapped the infiltration lifecycle these actors follow, from résumé to deepfake interview to identity verification to onboarding and provisioning. At each handoff, the process has a blind spot a prepared adversary can operate inside.
The résumé and application. Screening evaluates whether a candidate is qualified, not whether they're real. A tailored, well-written application clears the ATS, and the identity attached to it belongs to a real person, so nothing looks off.
The background check. This is the control most people assume is the backstop. It isn't, because it validates the stolen identity, which is genuine. The check answers "does this person exist and have a clean record?" The honest answer is yes. It was the wrong question.
The video interview. Seeing a face on camera feels like proof. Increasingly, it isn't. Operatives have used AI-augmented images, real-time deepfakes, and persona reuse across dozens of applications. But the hardest version to catch has nothing to fake at all: in at least two cases Abnormal observed during live interviews, the person behind a North Korea-linked persona was likely a U.S. citizen, providing legitimate identification and native fluency, with nothing for a deepfake detector to flag.
The device and the location. Companies often treat "U.S.-based remote worker" as reassurance. Laptop farms, where a domestic facilitator receives the company laptop and keeps it running from a home in the U.S., manufacture that reassurance. Combined with a VPN, the worker looks like they're logging in from down the street.
Here's what makes these blind spots so hard to close from inside a single company: no one application looks suspicious on its own. The tell is correlation. The same VoIP phone number, the same reused résumé template, or the same facilitator infrastructure surfaces across several companies in the same window, which is a pattern any one employer sees only in isolation, if at all.
Why the Gap Is Structural, Not a Screening Mistake
Notice what every one of those controls has in common: they verify a claim at a single moment in time, using documents and appearances. None of them observe how the person behaves once they're inside, and none keep watching after the offer is signed.
That's the structural gap, but verification is a snapshot. Impersonation reveals itself in motion, in the mismatch between how a genuine employee in that role behaves and how the fraudulent one does. In the KnowBe4 case, nothing in the vetting caught the operative. What caught them was behavior: a device doing something a new engineer's laptop shouldn't do, minutes after it powered on.
The takeaway isn't "add a fifth interview." KnowBe4 ran four. And you can't out-screen an adversary who brings a genuine identity, sometimes a genuine citizen, to the table. The detection that works has to move to signals that are hard to fake, and it has to continue past day one.
What You Can Do
No single fix closes a gap this structural, but a few shifts move the odds back in your favor:
Verify with signals that are hard to fake. A document and a face on a screen aren't enough. Weight device provenance, network and location consistency, and identity signals an impostor can't easily manufacture.
Keep watching after the offer. Treat provisioning and the first days of access as a monitored window, not a finish line. The behavior of a new account tells you what an interview can't.
Make it a shared security-and-HR responsibility. Decide in advance where security gets visibility into the funnel and who escalates what, so a suspicious signal has somewhere to go.
This is the kind of detection behavioral AI is built for. Abnormal's Infiltration Prevention applies the same behavioral approach that protects email and identity to the hiring pipeline, correlating signals across companies to surface a fraudulent persona for your security team before access is ever granted.

Where This Goes Next
If verification at the door can be defeated, the defense has to change shape: earlier visibility into the hiring funnel, and continuous attention to behavior after access is granted. The behavioral signals that expose a fraudulent identity show up before, during, and just after provisioning, which is exactly where behavioral AI does the work a checkpoint can't.

See how Abnormal closes the gap between identity provisioning and network access, before a fraudulent hire ever gets that far.
Explore Infiltration Prevention
Frequently Asked Questions
Can't we just add more interview rounds?
More rounds mostly add cost. The organizations that were infiltrated ran multiple interviews and still hired the operative. The issue is what interviews can verify, not how many you run.
Would requiring fingerprints or stronger ID verification solve it?
It helps, and it raises the cost for the attacker, which is worth doing. But no single document-based check is sufficient on its own. The adversary's advantage is a genuine identity, and in some cases a genuine person, fronting the persona.
Aren't deepfakes easy to spot?
They're getting harder to spot, not easier, and they now run in real time. More to the point, deepfake detection only helps when there's a fake to detect. When a real citizen sits for the interview, there isn't one.

