What it is
A deepfake candidate is a job applicant whose identity has been wholly or partly fabricated using generative AI in order to pass screening or a video interview. The term covers a spectrum, not one technique. At the simple end sits an AI-polished CV that invents experience or credentials that do not exist. In the middle sits a stolen or synthetic profile, a real person's photo and history repurposed under a false name. At the far end sits a live, real-time deepfake, a cloned voice or a face-swapped video feed used to impersonate someone else for the whole interview.
The most damaging variant for recruiters is the proxy interviewee: a different, often more technically capable person who sits the interview or the technical screen while posing as the applicant, sometimes coached live off-screen, while the person who actually turns up to do the job appears only weeks later. All of it shares one goal, getting past a screening process that was built for an era when the person on the call and the person who shows up were the same person.
A deepfake candidate only has to survive the interview. Verification has to survive everywhere else.
Why it matters
The scale is no longer marginal. Gartner's 2025 survey of hiring managers found 18% had already caught a deepfake candidate in a video interview, and 59% suspected AI-assisted misrepresentation in at least some of the candidates they saw. Gartner's longer forecast is blunter still: by 2028, one in four candidate profiles globally will be fake in some way. Security firm Pindrop reported that of 827 applications received for a single senior developer role, roughly 12% came from candidates using fake or deepfake identities, a sign of how concentrated the exposure is on remote, high-demand technical roles.
Recruitment agencies carry a specific version of this risk. A placed deepfake candidate is not just a bad hire, it is a shortlist the agency put its name behind, a fee exposed to clawback and a client relationship damaged at exactly the point it mattered most. That is part of why 72% of recruiting leaders now say they run in-person interview rounds specifically to counter this kind of fraud, reversing years of moving screening fully remote.
How boilr handles it
boilr does not claim to be a deepfake-detection tool, and no honest product does. What it does is shrink the surface a fabricated identity has to work with. Candidates and contacts surface through cross-referenced signals and public data across the sources boilr watches, not a single self-reported profile, and every contact runs through boilr's data waterfall to be checked against multiple sources before a task is drafted. A candidate history that does not hold up across sources is exactly the kind of inconsistency this stage is built to catch, before a consultant ever sees the task.
boilr is human-in-the-loop by design: nothing progresses and nothing sends without a consultant reviewing the task first, and the Company Brain carries your agency's own placement history alongside it, so a pattern that does not fit gets flagged against what you have seen before. That review is where judgement belongs. Pair it with the checks a deepfake candidate specifically calls for, an unscripted final round, a short proof-of-work task, a reference call placed to a number you found independently, and boilr's job is making sure that review starts from a shortlist worth trusting in the first place.