Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
Social Engineering Examples·8 sources
Vidoc Security Lab, a Polish-founded, US-headquartered remote-first startup building AI-assisted code security tools, was targeted twice within about two months (roughly December 2024 and 2025-02-04) by job applicants who used real-time deepfake/AI face-filter technology to disguise their real identity during video interviews for an open, Poland-based remote backend engineer role.
In the first case, a candidate using the name "Makary Krol" and claiming a Polish background passed resume screening, an HR call, and a full technical coding interview (finishing faster and more completely than any prior candidate) before cofounder Klaudia Kloc grew suspicious in the final non-technical interview: he could not speak any Polish despite the claimed background, and his personal details didn't hold up.
In the second case, a candidate using the name "Bratislav Rakočević" and claiming a Serbian background had spent weeks building rapport with the cofounders via LinkedIn before a role opened. During the live technical interview, cofounder Dawid Moczadło noticed the on-camera face looked artificial and didn't match the candidate's LinkedIn photo, and that answers sounded like scripted, ChatGPT-style bullet points.
Moczadło recorded the call and asked the candidate to place a hand in front of his face, a liveness test real-time deepfake filters typically cannot render, which the candidate refused, exposing the fraud on camera. Post-incident analysis showed the synthetic face resembled Polish politician Sławomir Mentzen, and Vidoc noted both personas shared a similar strong accent despite differing claimed nationalities, leading the company to suspect a single operator (or coordinated group) was behind both attempts, and possibly similar attempts at many other companies.
Vidoc publicized both incidents (blog postmortem, 2025-03-27) and the story was independently reported in depth by The Pragmatic Engineer newsletter (2025-03-11, based on a direct interview with cofounder Dawid Moczadło) and by The Register and other outlets.
Both fraud attempts followed Vidoc's normal remote hiring funnel: resume/CV screening, a 15-30 minute HR/operations screening call, a hiring-manager or technical coding interview, and a final non-technical interview. In case 1 ("Makary Krol," claiming a Polish background and a Warsaw University of Technology degree), the candidate had a polished, convincing CV and LinkedIn profile, spoke broken English with a strong accent flagged internally as unusual but not disqualifying, and became the first candidate in the hiring process to complete the entire timed 2-hour coding interview (including follow-up questions) with time to spare.
He passed resume screening, the HR call, and the technical/hiring-manager interview. Suspicion only crystallized in the final, non-technical interview with cofounder Klaudia Kloc, when he was unable to speak any Polish despite claiming to have grown up and studied in Poland, and gave inconsistent answers about his background, timezone, and former employers.
The interview was ended and no offer was made; this session was not recorded, so Vidoc had only notes, not video proof. In case 2 ("Bratislav Rakočević," claiming a Serbian background), the candidate had built rapport over weeks via unsolicited, polite LinkedIn messages before a role opened, and had a LinkedIn profile with real mutual connections at companies he claimed to have worked for.
He first tried to skip video ("camera not working") before joining on camera for the technical interview with cofounder Dawid Moczadło. Dawid immediately noticed the on-screen face looked artificial and mismatched the LinkedIn photo, the speech pattern resembled read-aloud, ChatGPT-style bullet points, and there was audio-video lag consistent with a real-time face-swap/deepfake filter.
Dawid deliberately kept the candidate talking, started recording, and then asked the candidate to place a hand in front of his face, a simple liveness test most real-time deepfake filters cannot render correctly. The candidate refused, exposing the ruse, and Dawid ended the call. Later frame analysis showed the synthetic face closely resembled Polish politician Sławomir Mentzen.
Vidoc's postmortem noted both personas shared a similarly strong, Asian-sounding vocal accent despite claiming different nationalities (Polish vs. Serbian), and that the second persona's answers felt over-rehearsed, as if the operator had already been through Vidoc's specific interview sequence before; this was the basis for the company's suspicion that one operator (or coordinated group) ran both personas, and possibly many more against other employers.
Lure: two well-groomed fake personas, "Makary Krol" (claimed Polish, Warsaw University of Technology grad) and "Bratislav Rakočević" (claimed Serbian), each backed by a convincing CV, an active LinkedIn profile with real mutual connections, and strong-to-exceptional live coding performance, including being the fastest candidate ever to finish Vidoc's full 2-hour timed coding interview.
The second persona had spent weeks building LinkedIn rapport with the cofounders before any role was even open. Tell: in case 1, the candidate claiming Polish nationality/education could not speak a word of Polish, and his biographical answers (timezone, past employers, schooling) didn't hold together under casual conversational questioning in the non-technical final round.
In case 2, the interviewer noticed an artificial-looking face mismatched to the LinkedIn photo, ChatGPT-style scripted answers, and audio/video lag; when directly asked to place a hand in front of his face, a simple test that breaks real-time face-swap filters, the candidate refused, immediately exposing the deception. Vidoc also flagged the second persona's oddly overconfident, seemingly pre-rehearsed answers as if he'd already been through this exact interview flow, feeding the suspicion both personas were run by the same operator.
Neither impostor was hired or paid. The first candidate ("Makary Krol") was quietly rejected after the final interview raised unresolvable doubts, but the encounter was not recorded, leaving Vidoc with only notes. The second candidate ("Bratislav Rakočević") was caught on a recorded call after refusing a hand-over-face liveness test; cofounder Dawid Moczadło ended the interview and later published the recording publicly.
Vidoc added a mandatory in-person (or strictly ID-verified, filter-free) final interview round to its hiring process, published a free ebook titled "Deepfake Fraud Prevention: 17 Practical Strategies to Detect Fake IT Workers" (title confirmed directly on Vidoc's own blog post) on detecting fake IT workers, and went public with both incidents via a company blog postmortem (2025-03-27) and a Pragmatic Engineer newsletter deep-dive (2025-03-11) based on an interview with Moczadło.
Vidoc reported being contacted afterward by dozens of other startups and larger tech firms describing similar experiences, some only discovering the deception after already hiring the person, suggesting a widespread, possibly coordinated campaign rather than an isolated incident.
This is one of the earliest and most thoroughly documented first-party case studies of real-time deepfake video filters being used offensively against a company's own hiring process, rather than against a bank or help-desk. It demonstrates that a candidate can pass CV screening, an HR screen, and even a rigorous, timed technical coding assessment while wearing an AI-generated face, meaning technical competence alone is not proof of identity, and that standard video-interview trust assumptions (a face on screen, an accent, a claimed home country) can all be faked concurrently.
It also surfaces the broader pattern, echoed by dozens of companies who contacted Vidoc afterward and independently reported in the West in connection with fraudulent North Korean overseas IT-worker schemes, that fully remote hiring pipelines at software companies are being probed at scale by fraudulent-identity operators, with security/access-sensitive employers (like a code-security startup) especially high-value targets if a fake hire succeeds.
Vidoc's and Pragmatic Engineer's recommended/adopted mitigations: (1) require candidates to disable all video filters/backgrounds and verify this visually at interview start; (2) record all interviews, including early screening calls, to preserve evidence and allow frame-by-frame review; (3) use an active "liveness" challenge mid-interview, e.g., asking the candidate to place a hand in front of part of their face, which breaks most real-time face-swap filters because the algorithm cannot render the occlusion correctly; (4) cross-check claimed nationality/background against basic cultural and language fluency (e.g., ask a claimed native speaker to answer in that language); (5) verify timezone, previous-employer, and biographical details for internal consistency; (6) add a mandatory in-person (or at minimum, live unfiltered, ID-verified) final round before extending any offer, which Vidoc adopted after these incidents; (7) require formal ID/notarized identity verification prior to onboarding, especially for full-remote hires; (8) treat unusually fast/flawless completion of timed technical assessments combined with weak conversational depth as a correlated red flag rather than assessing coding and communication independently.
Vidoc later published a free ebook titled "Deepfake Fraud Prevention: 17 Practical Strategies to Detect Fake IT Workers," confirmed directly on the company's own blog post, based on this experience.
Social Engineering Examples. “Deepfake Candidate Interview Fraud at Vidoc Security Lab (Polish-Founded/US-HQ, 2024-2025)”. Accessed 19 September 2026. https://socialengineeringexamples.com/vidoc-security-deepfake-candidate-interviews-2025
the operator(s) likely used OSINT sources such as LinkedIn, company blogs, and funding-announcement coverage (Vidoc's $2.4M raise was publicly reported in October 2024) to identify Vidoc as an early-stage, security-focused, fully remote employer actively hiring for a Poland-based backend role, consistent with reporting that these schemes target companies with valuable IP and permissive remote-hiring processes.
public hiring and funding announcements are hard to suppress without harming legitimate recruiting and PR, so the realistic control is not hiding this exposure but hardening the interview process a well-researched applicant will eventually reach.
the operator(s) built fabricated candidate identities, including a polished CV, an active LinkedIn profile with real mutual connections, and a real-time deepfake/face-swap video filter, likely assembled using commercially available or open-source face-swap tools plus AI-assisted writing for CVs and application materials matched to the job requirements.
vet claimed credentials and employment history against independent, hard-to-fake signals, for example contacting claimed former employers directly, since a convincing profile and mutual connections are not proof of a real underlying identity.
per Vidoc's account, this persona spent weeks sending polite, unsolicited LinkedIn messages to the cofounders before any role was open, pre-establishing familiarity that made the later application feel less like a cold approach.
treat unsolicited pre-role networking from unknown accounts as a neutral signal rather than a trust signal, and apply the same verification steps to warm leads as to cold applicants regardless of prior rapport.
fabricated CVs were submitted through Vidoc's normal job posting, and both personas passed a 15-30 minute HR/operations phone screen, exploiting the fact that early-stage screens are typically audio-only or low-friction and not designed to catch identity fraud.
add a lightweight identity-consistency check at the first live conversation, such as easily-verified biographical or cultural questions tied to the claimed background, rather than treating early screens as pure skills gates.
both personas performed strongly in live, timed coding interviews, in one case finishing faster and more completely than any prior candidate, using genuine or AI-assisted technical skill to build interviewer confidence ahead of the higher-scrutiny final round.
score technical performance and communication/identity signals independently rather than letting a strong coding result offset unresolved identity doubts, and treat unusually flawless completion paired with weak conversational depth as a correlated red flag.
candidates joined video interviews using a real-time deepfake/face-swap filter, in one case first attempting to avoid camera use entirely by claiming a broken camera or connection before eventually joining with the filter active.
require candidates to disable all video filters and virtual backgrounds and visually confirm this at the start of every video interview, and treat camera-avoidance excuses at the video stage as a reason to slow down rather than proceed.
candidates gave scripted, ChatGPT-style bullet-point answers, and Vidoc's postmortem noted a similarly strong accent across two differently-claimed nationalities plus audio-video lag consistent with real-time face-swap processing.
record all interviews, including early screening calls, so unusual speech patterns, accents, and audio-video lag can be reviewed frame-by-frame rather than relying on an interviewer's in-the-moment impression alone.
Vidoc's cofounders directly asked candidates to place a hand in front of their face, a simple occlusion test that most real-time deepfake filters cannot render correctly; both personas failed or refused this test, exposing the fraud before any hire was made.
build an active liveness challenge, such as a hand-over-face or unexpected lighting/angle change, into every final-round video interview as a standard, non-negotiable step rather than an ad hoc response to suspicion.
had either persona passed undetected, the goal was consistent with fraudulent employment, meaning securing an offer and onboarding to draw a salary under a false identity, with the added risk at a security company of gaining codebase/production access that could enable IP theft, backdoor insertion, or, per suspected DPRK-style overseas IT-worker schemes cited in reporting, sanctions-evasion revenue.
gate final onboarding on formal, ID-verified, in-person or live-unfiltered confirmation of identity before extending any offer or provisioning codebase/production access, which Vidoc adopted as a mandatory step after these incidents.
Browse by what this case has in common with others in the library.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
SEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
Hackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack.
Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
A single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials.
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.
A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.