At first, everything looked normal. But as soon as the new employee received his work laptop he began uploading malware onto the company network. The company stated that suspicious activity had been detected immediately and that they had responded within a matter of minutes. The damage was minimal, as new employees are initially granted only limited access. No suspicions had arisen beforehand. The company describes the recruitment process in a blog post: “CVs were checked, interviews were conducted, background checks were carried out and references were verified before the person was hired”.
Warning about North Korean hackers
A similar case in the US had already caused a stir. An IT employee, using the stolen identity of a US citizen, took part in several video job interviews, bypassing the usual background check procedures in the process, and was eventually hired – to work exclusively remote. As soon as he gained access to the internal systems, he secretly downloaded as much company data as possible. This went on for four months before it was noticed, at which point he was dismissed. The company subsequently received emails containing ransom demands, which included some of the stolen data and demanded payment of a six-figure sum in cryptocurrency.
As early as 2022, the FBI warned of North Korean hackers who, on behalf of their government, get themselves hired as IT specialists in Western countries. Their mission: to raise money for their own government. Their ploy: they apply for jobs that can be done exclusively whilst working remote.
The experiment begins
Such cases prompted British security researcher Jake Moore to investigate just how easy it is to land a job using a false identity. In a presentation at a security conference organised by the European security software company ESET, Moore reported on his experiment. Such deception attempts are often based on AI-powered deepfakes. This is made possible because, nowadays, most job interviews take place as online meetings. Moore therefore wanted to work not only with falsified data, but also with a falsified appearance. Generating deepfakes in real time – that is, posing as someone else live on camera during a conversation – is, according to Moore, far less technically difficult than it might initially seem, thanks to newer AI models. The only significant investment required was a very powerful graphics card to run the AI model.
The security specialist generated the face of a non-existent person and named him ‘Jack Moore’, which is quite similar to his real name. He created a completely new identity for this person, including social media profiles. This also included a LinkedIn profile, which he actively used to network with other people who seemed likely to be helpful for his planned activity. Using ChatGPT, he generated a suitable CV. In it, he claimed to have worked as a teacher for 14 years and subsequently spent four years in IT sales. In reality, Moore had spent a long time working on cybercrime with the British police before moving into the IT security sector.
How easily AI and deepfakes can be used to manipulate identities and trust is also demonstrated in the it-sa 365 session “Defending Against Adversarial AI & Deepfake Attacks”. An earlier experiment by Moore involving a compromised LinkedIn account and a deepfake video is also documented in the article “Real or fraud? Expert shows how to become a managing director with a LinkedIn hack and deepfakes”.
No idea? No problem! An AI agent helps Jake in the job interview
To complete his new identity, he still needed an ID card, as applicants are often asked in virtual job interviews to hold an ID card up to the camera to confirm their identity. Using Photoshop and ChatGPT, he produced the appropriate forged document in no time at all. Preparing for technical questions took a little longer, as Moore developed a Claude agent for this purpose. The agent was designed to generate and display three suitable answers every time he heard a question. In this way, Moore hoped to pass the job interviews without any specific job-related knowledge.
The entire preparation process had taken four months. He had now reached the point where he could start looking for suitable job vacancies. He applied for roles in IT sales and actually secured an interview. But suddenly he began to feel uneasy, as what he was planning could constitute a criminal offence. He therefore contacted the managing director and let him in on his plan. The managing director was very interested in the experiment and promised to keep it confidential.
Jake had applied for a job titled ‘MSP partner development executive’. He received an invitation to a virtual interview, during which he was interviewed by an IT specialist and an HR representative. His fears that his deception might be uncovered proved unfounded. Everything went well, although the IT specialist did emphasise at the end just how important cybersecurity was to the company.
To his great surprise, Moore received an invitation the next day for a second round of interviews. In this, he was to present how he intended to contribute to the company’s success. He had ChatGPT draw up the concept for this.
An AI specialist was also present at the second interview. Moore believed his anxiety must have been palpable to everyone. Yet his presentation was convincing and the interview took a promising turn. Afterwards, he wanted to call off the experiment; after all, he had managed to demonstrate how one could go through a job application process using a completely virtual identity. But a few days later, he received confirmation that he’d got the job, with an annual salary of GBP 38,000.
Second attempt as Jackie
A colleague then encouraged him to repeat the experiment in a second attempt using a fake female identity. Moore accepted the challenge. It took another four months before the AI was sufficiently set up. This time, it wasn’t just a matter of using AI to change the face; he also had to alter his build, voice, hair and behaviour – all in real time. The effort involved was far greater, as different AI systems were now required. He had to spend a great deal of time generating a natural-sounding female voice from a male one. The hands posed particular problems. AI generally seems to struggle with hands, he says. Moore therefore decided to avoid moving his hands as much as possible during online conversations and to keep them out of the frame. To be on the safe side, he would also reduce the resolution of the video camera. Ultimately, Jackie Morris – as he called his new identity – was created.
The relevant social media and LinkedIn profiles were quickly set up, followed by a suitable CV and a forged ID card. Once again, he claimed to have worked as a teacher for 14 years and then spent a few years working in IT.
Virtual marriage builds trust
To top it all off, he married Jackie Morris to Jack Morris – his first virtual identity – on his social media profiles. To boost credibility, he spared no detail and even created photos of the two of them walking on the beach with their dog. He posted these on Instagram. Many companies carry out background checks on job applicants, and details like these boost credibility. His posts received loads of likes – yet another factor that boosts credibility.
Playing it safe: faked connection problems
Before he began, he carried out numerous tests with his colleagues to ensure that his new identity – particularly his voice – sounded authentic. To be on the safe side, he also got himself a ‘kill switch’ so that he could cut the connection if necessary, should anything go wrong technically. To this end, he recorded a short video clip with a blurred still image, in which he repeatedly asked whether he could still be heard and pretended that he himself could no longer hear anything. He was able to bring up and play this video at the touch of a button before abruptly cutting the connection to save the situation.
He then applied for a number of roles, including one as a ‘Customer Acquisition and Engagement Specialist’. Another interview followed, which again went well, and this was to be followed by a second interview with an IT expert. He eventually passed this round as well. Finally, a third interview was scheduled, which was to focus on technical matters with his future colleagues. During this interview, he once again used his Claude agent – with success: his fake identity was awarded the job for this role as well.
Fake application more successful than 261 (real) candidates
There were 262 applications for this role, four people were invited for an interview, Moore reported, and his avatar was selected. This demonstrates what is possible with AI today and casts a frightening shadow over the future. In the age of deepfakes, the next attack might not look like malware. Instead, it could present itself as the perfect candidate. Analysts at Gartner predict that by 2028, one in four job applicant profiles worldwide could be fake.
How HR decision-makers can spot fakes
Most HR departments are unaware of such risks. Awareness-raising measures can help to address this. Appropriate training and education programmes have now become indispensable for many companies. In addition, the German Federal Office for Information Security (BSI) has listed the risks and countermeasures on a dedicated webpage.
How security awareness must respond to AI-powered attacks is explored in the it-sa 365 article “Awareness in the age of AI”.
For a deeper dive, the IT Security Talk “Human Factor & AI Awareness” and the article “AI in the workplace is becoming a risk – awareness training is essential” examine how human behaviour, AI use and emerging threats are changing security requirements.
At the top of the BSI’s list are awareness measures designed to train those affected to recognise fakes. “Many deepfake techniques produce artefacts, some of which are quite obvious. Knowing these artefacts can significantly improve the ability to detect fakes,” writes the BSI. Typical artefacts include:
- Visible transitions at the edges of the face
- Sharp contours, such as those of teeth, appear blurred
- Limited facial expressions
- Inconsistent lighting
- Turning the head leads to image artefacts
- A metallic-sounding voice, unnatural noises
- Incorrect pronunciation of certain words
- Unusual intonation
Jake Moore highlights further anomalies on an ESET webpage:
- Excessively smooth skin textures
- Facial abnormalities such as crooked eyes, distorted teeth or unusual blinking patterns
- Lip-syncing errors, i.e. the voice and mouth movements do not match
When it comes to recruitment processes, one thing is particularly important: a face-to-face meeting should always be arranged. If this is not possible – for example, due to a great geographical distance – trusted third parties can verify the person’s identity. Furthermore, all the details provided should be checked.
it-sa Expo&Congress 2026: Experience cybersecurity live
Deepfakes, AI-powered attacks, awareness and identity security are among the topics currently shaping the industry. From 27 to 29 October 2026, the IT security community will come together at it-sa Expo&Congress at Exhibition Centre Nuremberg. Take the opportunity to discover expert presentations and solutions and exchange ideas in person with cybersecurity experts.
Buy your ticket for it-sa Expo&Congress 2026 now
Sources
BBC: Firm hacked after accidentally hiring North Korean cyber criminal
knowBe4: North Korean Fake IT Worker FAQ
The Guardian: ‘Don’t accidentally hire a North Korean hacker,’ warns the FBI
Gartner: Gartner survey shows just 26 per cent of job applicants trust AI to evaluate them fairly
The Times: How my deepfake AI avatar beat 261 humans to land a tech job [Paywall]
ESET, Jake Moore: How to detect deepfakes: A practical guide to spotting AI-generated misinformation

