What changed in applicant screening
The old screening problem was scarcity: too few qualified candidates and too much manual sourcing. The new problem is mixed volume. A single job can attract hundreds of applications, and many of those applications are now produced or polished by AI tools. Some are honest candidates using technology to write more clearly. Others are low-quality submissions that copy the job description, exaggerate experience, or invent credentials.
That distinction matters. Using AI to improve grammar is not the same as fabricating employment history. Recruiters need a process that separates normal writing assistance from material misrepresentation. A blanket ban on AI-written resumes is nearly impossible to enforce and can punish candidates who simply needed help presenting real experience. A verification workflow is more practical and fair.
How large is the problem in 2025 and 2026
The numbers have moved well past anecdote. A 2025 survey of 874 HR professionals conducted by Software Finder found that 72% of recruiters had already encountered AI-generated fake applications, including fabricated work histories, invented references, and machine-written resumes. That figure covers a broad definition of "fake," from fully invented identities to resumes where real experience has been substantially inflated with AI assistance.
Screening data from live pipelines is consistent with that number. Cybersecurity firm Huntress, tracking applicants to its own open roles between September and November 2025, flagged 23.2% of applicants as fraud risks using AI-detection tooling. Brainner, an AI screening vendor, reports fraud rates of 20 to 45% in remote tech roles across 2025 and 2026 cohorts. Those ranges are wide because fraud rates vary sharply by role type, seniority level, and whether the position is fully remote.
Gartner has projected that one in four applicant profiles will be fraudulent by 2028, a figure that covers both outright fabrication and selective misrepresentation. The Federal Trade Commission's Consumer Sentinel Network data shows reported losses from job-related fraud grew from $90 million in 2020 to over $501 million in 2024, a 457% increase in four years. Not all of that is application fraud directed at employers; a portion reflects scams targeting candidates. But the directional signal is clear: the financial stakes of a weak integrity process are rising for both sides of the hiring relationship.
Perhaps the most telling data point is recruiter confidence, or the lack of it. A 2025 Checkr survey of 3,000 hiring managers found only 19% believe their current processes would catch fraudulent candidates before hire. The gap between the volume of fraud and the confidence level of the people meant to catch it is where the real operational problem lives.
Signals that deserve closer review
A suspicious application is rarely obvious from one signal. The pattern matters. A disposable email domain on its own may simply mean a candidate is privacy-conscious. A profile link on an unexpected domain might be a typo. A resume that matches the job description closely may be a motivated applicant. But when several signals appear together, the recruiter should slow down and verify before advancing.
Common signals include disposable email domains, profile links that impersonate LinkedIn or portfolio sites, unsafe link schemes, repeated application metadata across unrelated candidates, copied application answers, unusually similar CV text, and employment timelines that do not hold up against the candidate profile. None of these proves fraud. They are reasons to review the application with more care.
The key is to avoid turning a warning into a verdict. The system should say, "review this," not "reject this." That protects candidates and keeps hiring decisions accountable.
When fraud moves from the resume into the interview
Resume fabrication used to be the end of the fraud problem. A candidate submitted inflated credentials, passed screening, and the misrepresentation was discovered during reference checks or on the job. That window has now extended. AI tools have made it possible to sustain misrepresentation into the interview stage itself, and remote video interviews have created a new attack surface.
The FBI's Internet Crime Complaint Center (IC3) recorded 691 AI-related employment complaints in 2025, specifically flagging voice spoofing and potential voice deepfakes during online interviews. Experian's 2026 Future of Fraud Forecast named deepfake job candidates one of the five top fraud threats of the year. In a Gartner survey of 3,000 job seekers, 6% admitted to engaging in interview fraud, either by having someone else impersonate them during a video call or by impersonating someone else entirely. A separate survey of hiring managers found one in three had discovered a candidate using a fake identity or a proxy in a live interview.
These cases tend to cluster in roles where remote work is the default and where the value of access is high: software engineering, DevOps, cybersecurity, and finance. A fraudulent hire in any of those functions carries risks that go well beyond a poor performance review. They may include unauthorized access to systems, data exfiltration, or the introduction of supply chain vulnerabilities. The Jones Walker AI Law Blog has documented cases where a fraudulent candidate hired through a compromised interview process became the origin point of a significant data breach.
The recruiter response to this pattern does not require technology that did not exist last year. It requires process discipline that is already available. Ask candidates to hold up a handwritten note with their name and the date on camera. Use unexpected follow-up questions that require the candidate to recall specific details from earlier in the conversation. Request a brief screen share of their actual development environment or portfolio files. These steps are low-cost, preserve the candidate experience for legitimate applicants, and eliminate the most common deepfake and proxy techniques, which depend on pre-recorded footage or a second person following a script. Google and McKinsey are among the organizations that reintroduced mandatory in-person stages for certain roles specifically to counter this pattern.
Why fair review beats automatic rejection
Automatic rejection based on integrity signals is risky. Data can be incomplete, links can be mistyped, and legitimate candidates sometimes use privacy tools, temporary addresses, or sparse online profiles. If a system silently rejects those people, the hiring team may never know it excluded a qualified candidate for the wrong reason.
A fair process keeps humans in control. The ATS can highlight a warning, explain what triggered it, and put the candidate in front of the recruiter for manual review. The recruiter can then compare the CV, application answers, interview notes, references, and work samples. That is a stronger decision than relying on a black-box score.
A practical workflow for suspicious applications
Start by reviewing the warning in context. Check whether the signal is about contact data, profile links, duplicated content, or application behavior. Next, verify the underlying claim. If the issue is a LinkedIn mismatch, compare dates and titles. If the issue is a suspicious portfolio link, ask the candidate to confirm the correct URL. If the issue is repeated text, use the phone screen to probe for detail.
The best questions are specific. Ask the candidate what problem they solved, what tradeoffs they considered, who they worked with, what failed, and what they would do differently. Fabricated experience often sounds confident in general terms but lacks operational detail. Real experience usually includes context, constraints, and imperfect outcomes.
Documentation, legal exposure, and policy basics
Most hiring teams think about application fraud as a candidate quality problem. It also has a legal dimension that is easier to manage if the process is documented before a disputed decision arises. If a recruiter rejects a candidate based on an integrity warning and the candidate later claims discrimination, the organisation needs a contemporaneous record showing that the warning was based on verifiable application data, that a human reviewed it, and that the decision process was consistent across similar cases.
The HireRight 2025 Global Benchmark Report found that one in six business respondents had already experienced identity fraud during hiring, and another three in ten were unsure whether it had occurred in their organisation. That uncertainty is itself a governance problem. If a company cannot determine whether it has hired fraudulent candidates, it cannot defend its screening process in a regulatory or legal context.
Practical documentation for each suspicious application should include: what signal was flagged and by which system or reviewer, what verification step was taken and what the result was, who made the final decision and on what grounds, and whether the candidate was given an opportunity to clarify the signal before a decision was made. That last point matters in jurisdictions with fair hiring laws that require adverse action notices or candidate rights to contest inaccurate screening data.
On the policy side, a written application integrity policy does two things. First, it sets a consistent standard that recruiters can apply without improvising under time pressure. Second, it signals to candidates that the organisation takes credential accuracy seriously, which may deter low-effort fraud before a recruiter needs to spend time on it. The New York State Bar Association has outlined the legal considerations employers face when responding to fake job candidates, including obligations around data handling and the limits of automated disqualification. Even if your jurisdiction differs, the framework is useful for building a policy that a legal team can review and approve.
One area that is rapidly becoming a standard practice is requiring candidates to certify the accuracy of their application in writing, either as a checkbox with clear language or as a signed declaration before an offer is extended. That certification does not stop determined fraud, but it creates a contractual basis for rescinding an offer or terminating employment if a misrepresentation is discovered post-hire. The Yardstik 2025 hiring fraud analysis recommends pairing that certification with a background check from an accredited provider for roles with access to sensitive systems, financial data, or customer PII.
How Treegarden frames the problem
Treegarden treats candidate integrity as an advisory workflow. The warning icon on the candidate card is a prompt for manual review, not a fraud label. The candidate details panel explains the warning in plain language so the recruiter can decide what to verify next.
This is deliberately different from a "fake applicant detector" that claims certainty. In hiring, certainty is rare. The safer product decision is to show the recruiter where to look, keep the signal explainable, and preserve human oversight for every candidate decision.
For teams already using AI-generated resume detection checklists or application flood management workflows, integrity warnings add another layer of triage without replacing recruiter judgment.
Review applications with context
Treegarden helps recruiters manage high-volume pipelines with advisory AI, application integrity warnings, and human review built into the hiring workflow. Book a demo
Frequently Asked Questions
Does a warning mean the candidate is fake?
No. A warning means the application contains one or more signals that deserve manual review. It should never be treated as proof of fraud or used as the sole reason to reject a candidate.
What is the safest way to handle suspicious applications?
Review the signal, verify the claim, document the decision, and keep a human recruiter responsible for the outcome. Avoid fully automated rejection for integrity warnings.
Should companies ban AI-written resumes?
A blanket ban is difficult to enforce and can be unfair. A better policy is to allow writing assistance while requiring every claim about experience, credentials, and achievements to be accurate and verifiable.