Gartner predicted in November 2024 that 1 in 4 job applicants will be fake by 2028. The fraud already in progress is measurable — AI-generated headshots on LinkedIn, mass-submitted bot applications, and fabricated profiles that pass initial ATS screening. This guide covers what to look for and how to verify.
🕵️ Check Applicant Headshots — Free3 checks/day free · No account · Works directly on LinkedIn in Chrome
Gartner's November 2024 prediction covers several related but distinct types of fake applicants:
The AI-generated headshot is often the first verifiable signal. Unlike fabricated text (work history, credentials), which requires document verification to check, a headshot can be checked in seconds with the right tool.
AI-generated professional headshots have improved dramatically — the obvious tells of earlier models (wrong finger count, melted ears, garbled background text) are increasingly rare in portrait-focused outputs. What remains detectable at the pixel level is analyzed automatically by a detection tool. Visual tells that still sometimes appear:
Visual inspection catches some cases. For everything visual inspection misses, use a detection tool that analyzes pixel-level generation artifacts.
The two checks take under a minute combined and cover both main vectors: AI-generated faces (Faux Spy) and stolen real photos (reverse image search). Neither alone is sufficient — run both.
Check applicant headshots directly on LinkedIn
🕵️ Add to Chrome — Free3 checks/day free · No account · Works on any image in Chrome
An AI headshot is one signal. Treat these in combination — more flags together make a stronger case for additional scrutiny:
Thin LinkedIn history with no mutual connections
A fabricated profile will have few first-degree connections and almost no mutual connections with you or colleagues. Real professionals in any field accumulate a network over time. A profile with 50 connections after 10 years of claimed employment is suspicious.
Endorsements and recommendations from profiles with no photos or thin histories
Fake applicant rings sometimes endorse each other. If the recommenders also have AI-generated headshots or paper-thin profiles, the endorsements are fabricated.
Resume is perfectly optimized for the job description
AI resume tools tailor every bullet point to every job posting. A resume that mirrors your JD's exact language almost word-for-word — not just the keywords, but the sentence structure — may have been generated specifically for this application.
References are unverifiable or delay verification
Fake references are a real problem: some fraud operations provide "reference services" with real people who'll vouch for a fabricated work history. Ask references for specific details — a particular project, a technical decision, a conflict that was resolved — that a genuine colleague would know but a paid faker wouldn't.
Applies to many similar roles simultaneously at high volume
Bot-submitted mass applications are a volume play — the same identity applying to hundreds of jobs. Check if the candidate's LinkedIn shows them recently connecting with many people in your industry at once, or if their application came in within seconds of the posting going live on a job board.
Avoids or staggers video calls
A legitimate candidate should be able to do a live, unscheduled video call with camera on and steady connection. Reluctance to turn on camera, poor connection quality that conveniently prevents facial visibility, or repeated rescheduling are soft signals worth noting alongside harder evidence.
For candidates who make it past initial screening and show any combination of the above flags, one verification step is definitive for remote roles: request a live, unscripted video call where the candidate is asked to share their screen and walk through a real piece of work.
Ask them to open a file from a project they've described — a codebase, a spreadsheet model, a design file. Ask them to explain a decision they made. Ask what they would have done differently. A real professional can do this. A fabricated persona cannot produce real work artifacts on demand.
For roles with access to sensitive systems or IP, consider third-party identity verification services (e.g., Persona, Jumio) that verify government-issued ID against a live selfie — these are now standard for financial services hiring and are increasingly used in tech for sensitive roles.
Open their LinkedIn profile in Chrome, right-click the headshot, and click Investigate with Faux Spy — you'll get a verdict with a confidence score in seconds. Also run a Google reverse image search on the photo. Visually: look for unnaturally smooth skin, perfectly even lighting with no shadows, and a generic soft-blur background with no identifiable location.
Gartner predicted in November 2024 that 1 in 4 job applicants will be fake by 2028. The problem is concentrated in remote roles — where no in-person interview is required before employment — and in roles with access to valuable systems or IP. Most recruiters already encounter suspicious applications that pass ATS screening but fail at later verification stages.
Phone screens: yes — AI voice tools are convincing enough to pass a scripted phone interview. Video calls: harder but not impossible with deepfake technology. The most reliable defense is an unscripted, live screen-share request — ask the candidate to open and walk through real work from a project they've described. A fabricated persona can't produce work artifacts on demand.
No — but it is a significant red flag that warrants additional verification. Some candidates use AI-edited or AI-generated headshots for aesthetic reasons without intending to deceive. The combination matters: an AI headshot alongside a thin LinkedIn history, unverifiable references, and a perfectly optimized resume is a much stronger signal than the headshot alone.
Yes. Faux Spy works on any image visible in Chrome, including LinkedIn profile photos. Open the applicant's LinkedIn profile in Chrome, right-click their photo, and click Investigate. Works on applicant headshots, recruiter profiles, and any other images visible in your browser — no uploading or switching tabs needed.
Remote roles are the primary target — no in-person verification is required before employment begins. Roles with access to sensitive systems, codebases, or financial data are also disproportionately targeted, particularly by state-sponsored actors. Customer-facing roles and roles requiring professional licenses are lower risk because fraud is more easily detected through client interaction or credential verification.
3 checks per day, free, no account required. Works directly on LinkedIn profiles and any other website in Chrome.
🕵️ Add to Chrome — Free 🦊 Add to Firefox — Free