← All notes

Fraud & Verification

Deepfake candidates and interview fraud: how detection works

Synthetic video, cloned voices and read-from-ChatGPT answers are cheap now. How Lantern flags them in real time, and why a flag is never a rejection.

5 min readBy Herman Ko

Interview fraud in 2026 has three common shapes: synthetic video standing in for a real face, a cloned voice standing in for a real one, and a candidate reading answers off a model rather than producing them. Lantern detects all three in real time. What happens next is the part worth reading: a flag is never an auto-rejection — the evidence goes to the hiring team and a human makes the call.

We'll reason about mechanics rather than quote incident statistics. Fraud numbers in this space are mostly extrapolation, and a vendor selling detection has an obvious interest in the number being large.

What does interview fraud actually look like now?

Three patterns, in rough order of how often the mechanics come up.

  • Substitution. One person interviews, a different person takes the job. Historically this required a physical stand-in and a hiring process that never met the candidate twice; remote-first hiring removed the first constraint.
  • Synthetic presence. Generated video or a cloned voice presenting as the applicant, either to disguise a substitution or to obscure who the applicant is at all.
  • Answer laundering. The candidate is real and present, but the answers are being generated live and read aloud. This one isn't impersonation, which is why it needs to be handled differently.

The third case is the one hiring teams disagree about most, and reasonably so. There is a spectrum between preparing with a model and reading from one during the interview, and where a team draws the line is a policy decision that belongs to the team, not to us.

Why has this become a screening problem?

Because the cost of the attack collapsed while the cost of verification didn't. Generating a convincing voice or a passable talking-head video used to require skill, time and money; it now requires none of the three in meaningful quantity.

Meanwhile the defence most processes relied on was incidental rather than designed. In-person interviews verified identity as a side effect of being in a room. Remote hiring dropped that side effect without replacing it, and for years the gap didn't matter because exploiting it was hard. That's the asymmetry that changed, and it's why verification has to become an explicit stage rather than an assumption.

Why does a live adaptive interview make fraud harder?

Because it doesn't let the answer be prepared in advance. The follow-up is generated from the specific thing the candidate just said, so there's no question list to obtain and no script that survives contact with the conversation.

That property does two jobs at once. Against answer laundering, the constraint is time: a genuine follow-up about the thing you said forty seconds ago has to be answered now, and the round-trip to generate something plausible is visible in the shape of the conversation. Against synthetic presence, adaptivity means the pipeline has to sustain a real-time, unscripted, two-way exchange rather than render a prepared clip. Neither is impossible to defeat. Both are considerably harder than answering a fixed question list into a recorder with two retakes, which is one of the quieter arguments for the format — see AI interviewer vs. one-way video interview.

What does Lantern flag?

Deepfaked video, cloned voices, and AI-generated scripts, detected during the interview rather than in a report afterwards. The output is a flag with the transcript moment attached, in the same structure as every score the system produces.

The design constraint is that a flag has to be inspectable. A detection signal a hiring team can't examine is a verdict wearing a probability, and it would sit badly next to the rest of the product — every score Lantern produces links back to the exact moment that earned it, and a fraud signal that arrived without evidence would be the one unauditable object in an otherwise auditable record.

Why not just auto-reject a flagged candidate?

Because detection is probabilistic and rejection is not. A false positive on a fraud signal doesn't cost a hiring team a candidate — it accuses a real person of dishonesty in a process that gives them no way to answer.

The benign explanations are numerous and boring. Poor bandwidth degrades video in ways that resemble generation artefacts. Noise suppression and beauty filters alter a face and a voice. A candidate reading from their own notes about their own project looks, from a distance, like a candidate reading from something else. Any of those can produce a signal; none of them is fraud. And the compliance argument points the same direction: an automated system making a final selection decision on a detection signal is a materially different regulatory object from one that produces evidence for a human, which is the boundary described in how we approach the EU AI Act.

What should a hiring team do with a flag?

Treat it as a reason to verify, not a reason to conclude. The useful response is almost always another conversation.

  1. Read the evidence first. The flag points at a moment. Look at what was happening then before deciding what it means.
  2. Decide your policy before you need it. Whether reading from a model is disqualifying, and for which roles, is a question you want answered in writing rather than improvised on a Friday.
  3. Verify rather than accuse. A short live conversation resolves substitution and synthetic presence quickly, and costs an innocent candidate nothing but time.
  4. Log the decision. Whatever you conclude, the reasoning belongs in the audit trail alongside the flag that prompted it.

Common questions

Does detection work across all 40+ languages?

The signals detection relies on are largely acoustic and behavioural rather than lexical, and Lantern interviews natively in every language it supports rather than in translation. As with any claim we make about multilingual behaviour, we'd rather you tested it on your own candidate mix than took a blanket assurance.

Is the candidate told they were flagged?

That's the client's call, because the client owns the decision and the communication. Our part is making sure the hiring team has the evidence and knows it's evidence.

Does this replace identity verification?

No, and it shouldn't be sold as one. Detection tells you something about the interview; formal identity and right-to-work checks tell you something about the person. They answer different questions and a serious process runs both.


If verification is the part of your process you're least confident about, that's a reasonable thing to test on a live req. Ask us to show it.