case file 03deepfakeMarch 2025Poland, remote pipeline
put your hand in front of your face
Hiring for one backend role out of about 500 applicants, security startup Vidoc got two AI-deepfaked candidates deep into its pipeline. One was exposed by a request that took three seconds: cover part of your face with your hand.
2
deepfaked candidates in one pipeline
~500
applicants for the role
3 sec
to break the filter
what happened
Vidoc Security Lab was hiring a backend engineer. Two of the candidates who reached late-stage interviews were not real people on camera. They were real people running real-time face filters, presenting as somebody else.
The first, presenting as a Polish engineer, passed the technical screen with genuinely strong coding. The second, presenting as a Serbian engineer, raised suspicion because the face moved slightly wrong. Co-founder Dawid Moczadlo asked him to put a hand in front of his face and partially cover it. Real-time face-swap software of the kind being used cannot keep the mask locked when a hand crosses the face. The illusion broke on camera.
Both candidates claimed nationalities whose language they could not speak. They appeared to share a voice and an interviewing pattern, which suggested the same operator behind more than one persona.
“Can you take your hand and put it in front of your face and cover it partially?”
Dawid Moczadlo, Vidoc Security Lab co-founder, mid-interview
how it was caught
By a human being who was already suspicious, on a video call, in real time, and who happened to know the right test to ask for. That is not a process. That is luck plus a security founder's instincts.
Vidoc published the footage and the method. It became the single most widely shared demonstration of what a deepfaked candidate actually looks like in an interview.
what it cost
Vidoc hired nobody fraudulent, so the direct cost was interview time across a pipeline of around 500 applicants and the two late-stage loops that were wasted.
The real cost is the counterfactual. The first candidate coded well enough to pass the technical screen. Without a founder who thought to ask for a hand wave, he would have received an offer.
the tells
signals that were visible, in hindsight, before anyone was hired.
- The face moves slightly out of sync with the mouth, especially on fast speech.
- The filter fails when a hand, a cup, or any object crosses in front of the face.
- A claimed nationality without the language that goes with it.
- Two different candidates who sound like the same person and interview the same way.
- Lighting on the face that does not match lighting in the room behind it.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
A live person and a rendered overlay do not behave the same way. NeuralPrint reads a candidate continuously through the session rather than at one moment they can prepare for, so the difference shows up as a measurement instead of a hunch.
A rendered face drifts. Reading the candidate throughout the interview, rather than checking once at the start, is what turns that drift into something you can act on.
Two personas run by one operator have things in common. Looking across the whole applicant pool catches what an interviewer meeting one candidate never sees.
sources
- [1]AI fakers: how deepfaked candidates got deep into a startup's hiring pipeline
The Pragmatic Engineer · firsthand account · March 11, 2025
Gergely Orosz's account of Vidoc Security. The hand-in-front-of-face test that broke the filter came from co-founder Dawid Moczadlo.
- [2]North Korean IT workers: indicators and mitigations for hiring teams (PSA)
FBI Internet Crime Complaint Center · fbi · July 23, 2025
The most detailed FBI list of hiring-stage red flags: camera refusal, face-swap artefacts, ID mismatch, laptop shipping address changes, shift changes between interview and work.
- [3]Jasper Sleet: North Korean remote IT workers' evolving tactics to infiltrate organizations
Microsoft Threat Intelligence · security research · June 30, 2025
3,000 accounts suspended. Documents face-swap edits onto stolen IDs, voice changers in interviews, and Astrill VPN plus remote-management tooling.
more case files
north korean it scam · July 2025
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
north korean it scam · July 2024
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
proxy interview · October 2025
from Jalisco, without the Spanish
Bitso's security team documented two applicants for a senior engineering role who used stolen resumes and AI-generated faces, said they were from Jalisco and Chihuahua, and could not speak Spanish. Their LinkedIn profiles vanished after the interviews.