Job and recruitment scams steal money, personal information and system access, and in 2026 the fastest-growing version targets the hiring side, not just the job seeker. This guide trains staff to spot fake job offers and to catch deepfake candidates before they reach onboarding.
Why this matters
Recruitment scams run in two directions. One targets job seekers with fake postings, upfront fees or work-from-home schemes. The other targets employers: a synthetic candidate joins a video interview, passes screening, and once hired gains system access or steals data.
Experian's 2026 Future of Fraud Forecast rates employment fraud as the second-highest fraud threat this year and names AI-generated deepfakes as the reason it is accelerating. The FBI and multiple security firms have documented cases where a deepfake candidate passed a live video interview, was hired into a remote engineering or finance role, and then compromised internal systems or exfiltrated data. Jones Walker's 2026 analysis of the trend calls it exactly what it is: a data breach that starts with a job interview.
On the job-seeker side, Australia's National Anti-Scam Centre stood up a dedicated fusion cell to tackle job and employment scams after Scamwatch reports rose 151% in 2023 to 4,830 reports and $24.3 million in losses. Reported losses were trending down through 2024 but still reached $6.4 million partway through the year. These scams have not gone away - they have shifted to also targeting the businesses doing the hiring.
What you will need
- A record of your organisation's actual recruitment workflow: screening calls, video interviews, offer letters, onboarding and system provisioning.
- The job titles and contact channels your hiring managers actually use, so staff can recognise a mismatch.
- A list of the recruitment platforms and agencies you use (LinkedIn, SEEK, internal ATS).
- A named HR or security contact staff can escalate to when something looks wrong.
- Cyber Aware training access for follow-up lessons after a test or a real incident.
Step 1: teach hiring staff the deepfake warning signs
Real-time deepfake video is convincing enough in 2026 to pass a live interview, and it responds to questions rather than just playing back a loop. Train hiring staff to notice: unnatural stillness or lighting that never shifts; answers that arrive a beat late or drift off-topic; no ambient sound at all despite a claimed home or office setting; and identical clothing, framing or phrasing across separate calls with the same person.
Common mistake: treating a slightly awkward video call as ordinary nerves rather than a signal worth a second look. Nerves and deepfake artefacts look different once you know what to compare against.
Step 2: require a liveness check before offer or system access
This is the single control that stops a deepfake hire. Before an offer is confirmed or any system access is provisioned, require the candidate to do something unscripted on camera: show a government ID at an angle you request, point to a specific object in their space, or answer a question that was never on their application. Deepfakes fail this test because they cannot improvise physical action in real time.
For high-sensitivity roles - finance, engineering, anything with data or system access - add a second interviewer to the final call and confirm a detail that was never written down anywhere the candidate could have prepared it. For on-site roles, do not activate logins until an in-person identity check has happened.
Expected outcome: a fake candidate is caught before they hold a login, not after. Common mistake: running liveness checks only for senior roles - deepfake attempts documented in 2026 have targeted mid-level remote engineering and support positions just as often.
Step 3: verify the recruiter or agency before trusting the contact
Scammers spoof recruiters from real agencies using lookalike domains. Teach staff to check the sending domain against the agency's actual site, call the agency's published switchboard number (never a number supplied in the email) and ask for the named recruiter, and treat generic, copy-paste outreach with spelling errors as a red flag rather than a busy recruiter's shorthand.
The risk is not abstract. The ACCC's Coffs Harbour case - a strata manager who made 398 fraudulent transactions across 66 client accounts before her licence was cancelled - shows how far a single trusted, unverified contact can go inside a business relationship. A recruitment channel deserves the same scepticism as a finance one.
Step 4: train employees to spot scam job offers aimed at them
Employees also receive fake offers directly. Give them four questions: Does the company's name, ABN and domain match public records, or is the salary suspiciously high for the role? Did I apply, or was I contacted unsolicited on WhatsApp, Telegram or Instagram? Is there any request for money upfront - equipment, training, background-check fees? Can I find the named hiring manager on the company's own site or LinkedIn?
A legitimate employer never asks a candidate to pay before starting. That single rule catches most of what is left after the deepfake and agency checks.
Step 5: document the safe recruitment workflow for your organisation
Publish a one-page reference: what domain hiring managers actually email from, how interviews are scheduled (always through official channels, never an unsolicited text), what ID is requested and when, and a named contact candidates can call to confirm a real offer. This protects your hiring team as much as it protects candidates, because it gives a genuine applicant an easy way to check a message that claims to be from you.
Step 6: run a simulated recruiter contact
Send hiring staff a mock message from a lookalike recruiter domain, complete with urgency language, a vague title and a request to move to WhatsApp. Track who forwards it to HR, who clicks through, and who calls to verify. Follow up individually - a quick coaching note for anyone who engaged without checking, a thank-you for anyone who caught it. Run this alongside your existing phishing simulations so recruitment-themed lures sit in the same rotation as invoice and delivery scams.
Troubleshooting
Hiring managers say verification calls take too long. A 60-second script works: call the agency's main line, ask for the recruiter by name, confirm they are handling this role. If they are unknown, stop and investigate before responding further.
Candidates push back on liveness checks. Frame it plainly: "We verify every candidate this way because recruitment scams are common in 2026 - it protects you as much as us." Genuine applicants generally accept this without friction.
A suspicious offer or candidate message arrives. Do not reply, click any link, or call any number in the message. Forward it to your named HR or security contact and let them investigate through verified channels.
Tools and resources
- Cyber Aware training
- Cyber Aware phishing simulations
- Cyber Aware gap assessment
- ACCC Scamwatch - job and employment scams fusion cell
FAQ
Can a deepfake really pass a live video interview in 2026? Yes. Real-time deepfake video can convincingly mimic a person's face and voice and respond naturally to questions. Its weakness is unscripted physical action - asking a candidate to show an ID at an unusual angle or point to something specific defeats it.
What should a hiring manager do if they suspect a deepfake candidate? Stop the interview without alerting the candidate to your suspicion, document what you observed, and report it to your security or HR team immediately rather than continuing the process.
Should video interviews be replaced with phone calls to avoid this risk? No. Phone calls offer no visual verification at all. A video interview paired with a liveness check is stronger than either format alone.
Is in-person onboarding required to stop deepfake hires? For roles with data or system access, yes, or an equivalent rigorous liveness check with a second witness. Lower-risk roles can rely on the liveness check alone.
How common are job scams in Australia right now? Scamwatch recorded 4,830 job scam reports and $24.3 million in losses in 2023, a 151% jump on 2022, prompting a dedicated National Anti-Scam Centre fusion cell. Losses were still running at $6.4 million partway through 2024.
Do recruitment scams only target job seekers? No. In 2026 the faster-growing risk is the reverse: a synthetic candidate targeting the employer to gain system access or steal data once hired.
One last thing
The organisations catching deepfake candidates in 2026 are not using better software - they are asking one unscripted question the candidate cannot have prepared for. Build that single step into your final interview and you close the gap that most recruitment fraud walks straight through.