Synthetic Candidates: Fully Fabricated Applicants Built From Stolen Identity Data

Abinayasree C

Updated on September 4, 2026

Synthetic Candidates: Fully Fabricated Applicants Built From Stolen Identity Data

Abinayasree C

Updated on September 4, 2026

In this post

CREATE YOUR ACCOUNT

Accelerate the hiring of top talent

Make talent quality your leading analytic with skills-based hiring solution.

Get started

A synthetic candidate is a job applicant who does not exist as a single real person at all. The persona is assembled, usually by combining stolen or purchased personally identifiable information (PII) with an AI generated resume, an AI generated or composite photo, and an invented work history, into a package that looks, on paper and often on screen, like a plausible human candidate. Nobody actually lived the career the resume describes, and no single person may even be operating the persona consistently from one hiring stage to the next.

That distinction is the whole point of this post. Most “candidate fraud” coverage lumps together three very different problems: a real person who pads their own resume, a real person who sends a stand in to their interview, and a real person who works under someone else’s stolen identity. Synthetic candidates are a fourth, newer category, and arguably a more structural one, because the fabrication happens at the pipeline level rather than the individual level. Gartner’s now widely cited forecast puts a number on how fast this is scaling: one in four candidate profiles worldwide are expected to be fake by 2028.

What Makes a Candidate “Synthetic,” Specifically

A synthetic candidate is not the same thing as any of the more familiar fraud types already covered on this site, and the difference matters because each one needs a different control to catch it.

  • Resume embellishment is a real person exaggerating their own real experience, for example using AI to inflate a job title or invent a metric on a resume that otherwise describes a career they actually had.
  • Proxy interview fraud is a real, different person standing in for the applicant during the interview itself, while the applicant on paper still exists.
  • Stolen identity employment fraud, the pattern behind most reported remote IT worker schemes, is a real operative who has taken over or purchased someone else’s genuine identity to get hired themselves.
  • A synthetic candidate has no single real person underneath it at all. The name, work history, and often the face are generated or assembled specifically to apply for jobs, and the persona may be reused across dozens of applications or even operated by different people at different stages of the same hiring process.

Sardine.ai, which builds fraud detection tools, frames the practical test simply: is the candidate in front of you actually a person, or is what you are evaluating a construct built to pass your screening steps. Staffingindustry.com’s 2026 analysis of the trend, titled “AI synthetic identities: The fraud inside the candidate pipeline,” describes the same shift: fraud that used to require one convincing liar now only requires assembling the right combination of stolen data and generative tools.

How a Synthetic Candidate Actually Gets Built

The pipeline behind a synthetic candidate typically has three components, and generative AI has made each one dramatically cheaper and faster to produce than it was even two years ago.

Stolen or purchased PII. Real names, Social Security numbers, dates of birth, and addresses, sourced from prior data breaches or purchased on illicit marketplaces, give the persona a data trail that can survive a shallow identity check. This is the same raw material behind synthetic identity fraud in banking and lending, a longer established category, now redirected at hiring pipelines instead of credit applications.

AI generated resumes and work histories. A large language model can produce a fluent, keyword optimized, internally consistent career narrative in minutes, tuned to whatever job description it is aimed at. Metaview’s research on candidate fraud found that 39 percent of candidates now use AI somewhere in the application process, and among that group, 83 percent admit to exaggerating or outright fabricating skills and experience, according to Capterra survey data cited in the same research. A synthetic candidate pushes that same generative capability past embellishment into total invention.

AI generated or composite photos and, increasingly, video. A generated headshot or a face assembled from stolen images gives the persona a visual identity to match its paperwork, and the same generative tooling that produces convincing images increasingly extends to short video clips or voice samples used to get past an initial screening step.

Recruitics describes this as a spectrum rather than a single behavior: on one end, a real person uses AI to polish their own materials; on the other, an entirely fabricated identity shows up “often accompanied by deepfake video and false credentials.” Synthetic candidates sit firmly at that far end of the spectrum.

Why This Is Growing So Fast in 2026

Several forces are converging at once to make synthetic candidates a bigger problem this year than the concept even had a name for two years ago.

Application volume has exploded well past what human reviewers can sanity check. GoodTime’s 2026 Hiring Insights Report, covered by cumberlink.com, found that job applications grew roughly four times faster than open roles in a recent measured period, a 31 percent year over year increase, while 99.8 percent of talent acquisition teams reported they are already using, piloting, or planning to use AI agents somewhere in their own hiring process. Fraud and legitimate volume are both scaling on the same underlying technology.

The economics favor the fraud, too. Sardine.ai’s research lists the motivations behind synthetic applicants: stealing data and intellectual property once hired, committing customer or vendor fraud from inside a company, claiming a role purely for salary arbitrage tied to a fabricated location, and organized rings running the same persona template against many employers at once. Staffinghub.com reports that reported job related fraud losses climbed from about 90 million dollars in 2020 to over 501 million dollars in 2024, a 457 percent increase in four years.

Confidence has not kept pace with the threat. Checkr research cited by Metaview found that only 19 percent of hiring managers are extremely confident their current process would catch a fraudulent applicant, while 62 percent believe candidates have gotten better at faking identities faster than recruiters have gotten better at spotting it. Remote and distributed roles carry the sharpest exposure: the same research found remote positions receive roughly ten times more fraudulent applications than in person roles, since a synthetic candidate never has to survive being physically present anywhere.

Why Background Checks Alone Miss Synthetic Candidates

A standard background check answers one question: does this Social Security number, name, and address combination have a clean record. It does not answer the question that actually matters for a synthetic candidate: is the person submitting this application the same person that data belongs to, or is there no real person behind it at all. Staffinghub.com’s reporting puts this plainly: a background check “can’t tell you whether the person being evaluated is the same person who applied.”

A synthetic persona can carry a clean, boring identity record precisely because the PII underneath it belongs to a real, unrelated person who has never touched the hiring process. The fabrication is in the connection between the data and the applicant, not in the data itself, which is why identity verification has to check that link directly rather than checking the data in isolation.

How To Detect a Fully Fabricated Candidate

Because there is no real person consistently behind a synthetic candidate, its fabrication tends to leave a distinct signature that differs from a person merely lying about their own background.

  • Biometric identity verification at the point of hire. Matching a government issued ID against a live selfie with liveness detection confirms a real human is present and that they match the document, something a purely generated persona cannot do on demand.
  • Cross platform digital footprint checks. A LinkedIn profile created the same week as the application, a resume timeline that does not line up with any other public trace of the person, or a phone number that fails a basic trace are all signs research groups consistently flag as synthetic indicators rather than simple embellishment.
  • Work history verification through references. Since a synthetic candidate’s employment history is generated rather than lived, structured reference checks that verify dates, titles, and reporting lines directly with named contacts tend to surface fabrication that a resume alone hides. Automated reference checking tools built for hiring, rather than manual reference calls that are easy to script around, make this step feasible at volume.
  • Coordinated application patterns. Recruitics flags clusters of applications arriving within minutes of each other, using near identical formatting and language, as a signature of a template being reused across many synthetic personas rather than individual candidates writing separately.
  • Skills based verification. A resume can claim any skill; a live, job specific task is much harder to fabricate an answer for on the spot, which is why pairing identity checks with practical assessment closes a gap neither control closes alone.

Related, Narrower Fraud Patterns To Know

Synthetic candidates sit alongside, but are distinct from, two other patterns already well documented in hiring fraud. Deepfake driven candidate fraud, covered in detail in glider.ai’s piece on deepfake technology and candidate fraud, involves a real individual using face swapping or voice cloning tools to impersonate someone else live on camera, a different mechanism than a persona with no operator to unmask. Candidate fraud from North Korea describes a specific, extensively documented state sponsored scheme, in which a real operative works under a stolen identity, often with the help of a US based facilitator running a so called laptop farm, to gain remote access to a company’s systems. Both are serious, real world patterns worth understanding on their own terms. Synthetic candidates are the broader, newer category underneath them: the assembly line that can produce a plausible fake applicant for any of these purposes, not tied to one nation, one motive, or one operator.

How Glider AI Helps Catch Synthetic Candidates

Glider AI’s ID Verify product is built specifically for the gap a background check leaves open: confirming that the person applying, interviewing, and showing up on day one is the same real, single individual throughout, using government ID validation, biometric facial matching, and duplicate application detection across a company’s full candidate pool. Paired with skills based assessment and structured reference checking, it closes the loop a synthetic candidate depends on staying open: a resume nobody has to prove, a photo nobody has to match, and a work history nobody actually calls to confirm.

FAQs

What is a synthetic candidate?

A synthetic candidate is a job applicant persona that does not correspond to any single real person. It is built by combining stolen or purchased PII with an AI generated resume, photo, and work history, so it can pass an initial screen without a real individual’s career actually existing behind it.


How is a synthetic candidate different from resume fraud?

Resume fraud, including AI resume fraud, involves a real person exaggerating or fabricating parts of their own actual work history. A synthetic candidate involves no real underlying person at all; the entire identity and history are assembled rather than exaggerated.

How is a synthetic candidate different from a proxy interview?

In a proxy interview, a real applicant exists on paper, and a different real person stands in for them during the interview itself. A synthetic candidate has no real applicant on paper to begin with.

How is a synthetic candidate different from the North Korean IT worker scheme?

That scheme, and similar stolen identity employment fraud, involves a real operative working under someone else’s genuine stolen identity. A synthetic candidate may not have a single consistent human operator behind it at all, and is not tied to any one nation or motive.

How common are synthetic candidates today?

Exact counts for fully synthetic personas specifically are still emerging, but Gartner’s broadly cited forecast estimates one in four candidate profiles worldwide will be fake by 2028, and Checkr research cited by Metaview found only 19 percent of hiring managers are extremely confident their process would catch a fraudulent applicant today.

Can background checks catch synthetic candidates?

Not reliably on their own. A background check verifies that a given identity’s record is clean, but it does not verify that the person applying is the same person that identity belongs to, which is the exact gap a fabricated persona is built to exploit.

What is the best way to prevent synthetic candidates from getting hired?

Layering biometric identity verification, cross platform digital footprint checks, structured reference verification, and skills based assessment closes the gaps that any single control misses, since a synthetic persona is built to survive a shallow, one dimensional check rather than a layered one.

Why are synthetic candidates increasing in 2026?

Generative AI has made every component of a fabricated persona, the resume, the photo, and sometimes short video or voice, cheap and fast to produce, while application volumes have grown faster than review capacity, according to 2026 hiring data reported by GoodTime and covered by outlets including cumberlink.com.

Global Hiring Fraud Hotspots: Where Candidate Fraud Risk Is Highest in 2026

Global hiring fraud hotspots are the countries and regions where documented candidate fraud and identity verification risk run highest, based on named industry indices rather than assumption. In 2026, that data points consistently in one direction: fraud vulnerability is concentrated in markets with weaker centralized identity infrastructure and fast growing digital hiring volume, led by […]

Hiring Overqualified Candidates: The Hidden Risk and Reward Employers Weigh

Hiring overqualified candidates is not automatically a mistake, but it is a decision that carries real, well documented risk if the role and the offer are not restructured around it. Recent survey data shows most employers already do this regularly: 70 percent of hiring managers say they typically consider candidates who are overqualified for the […]

Candidate Net Promoter Score (CNPS): How to Measure and Use It

Candidate Net Promoter Score (CNPS) is a recruiting metric that asks candidates how likely they are, on a 0 to 10 scale, to recommend applying to your company to someone else. Subtract the percentage of detractors (scores 0 to 6) from the percentage of promoters (scores 9 to 10) and you get a single number, […]

chevron-down