Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup, caught two separate job candidates using real-time AI deepfake video filters to disguise their identity during technical interviews for a Poland-based remote role, and suspected, based on matching vocal accents and one persona's oddly over-rehearsed answers, that both fake personas were run by the same operator.
Reviewed by the Social Engineering Examples team.
Vidoc Security Lab, a Polish-founded, US-headquartered remote-first startup building AI-assisted code security tools, was targeted twice within about two months (roughly December 2024 and 2025-02-04) by job applicants who used real-time deepfake/AI face-filter technology to disguise their real identity during video interviews for an open, Poland-based remote backend engineer role. In the first case, a candidate using the name "Makary Krol" and claiming a Polish background passed resume screening, an HR call, and a full technical coding interview (finishing faster and more completely than any prior candidate) before cofounder Klaudia Kloc grew suspicious in the final non-technical interview: he could not speak any Polish despite the claimed background, and his personal details didn't hold up. In the second case, a candidate using the name "Bratislav Rakočević" and claiming a Serbian background had spent weeks building rapport with the cofounders via LinkedIn before a role opened. During the live technical interview, cofounder Dawid Moczadło noticed the on-camera face looked artificial and didn't match the candidate's LinkedIn photo, and that answers sounded like scripted, ChatGPT-style bullet points. Moczadło recorded the call and asked the candidate to place a hand in front of his face, a liveness test real-time deepfake filters typically cannot render, which the candidate refused, exposing the fraud on camera. Post-incident analysis showed the synthetic face resembled Polish politician Sławomir Mentzen, and Vidoc noted both personas shared a similar strong accent despite differing claimed nationalities, leading the company to suspect a single operator (or coordinated group) was behind both attempts, and possibly similar attempts at many other companies. Vidoc publicized both incidents (blog postmortem, 2025-03-27) and the story was independently reported in depth by The Pragmatic Engineer newsletter (2025-03-11, based on a direct interview with cofounder Dawid Moczadło) and by The Register and other outlets.
Both fraud attempts followed Vidoc's normal remote hiring funnel: resume/CV screening, a 15-30 minute HR/operations screening call, a hiring-manager or technical coding interview, and a final non-technical interview. In case 1 ("Makary Krol," claiming a Polish background and a Warsaw University of Technology degree), the candidate had a polished, convincing CV and LinkedIn profile, spoke broken English with a strong accent flagged internally as unusual but not disqualifying, and became the first candidate in the hiring process to complete the entire timed 2-hour coding interview (including follow-up questions) with time to spare. He passed resume screening, the HR call, and the technical/hiring-manager interview. Suspicion only crystallized in the final, non-technical interview with cofounder Klaudia Kloc, when he was unable to speak any Polish despite claiming to have grown up and studied in Poland, and gave inconsistent answers about his background, timezone, and former employers. The interview was ended and no offer was made; this session was not recorded, so Vidoc had only notes, not video proof. In case 2 ("Bratislav Rakočević," claiming a Serbian background), the candidate had built rapport over weeks via unsolicited, polite LinkedIn messages before a role opened, and had a LinkedIn profile with real mutual connections at companies he claimed to have worked for. He first tried to skip video ("camera not working") before joining on camera for the technical interview with cofounder Dawid Moczadło. Dawid immediately noticed the on-screen face looked artificial and mismatched the LinkedIn photo, the speech pattern resembled read-aloud, ChatGPT-style bullet points, and there was audio-video lag consistent with a real-time face-swap/deepfake filter. Dawid deliberately kept the candidate talking, started recording, and then asked the candidate to place a hand in front of his face, a simple liveness test most real-time deepfake filters cannot render correctly. The candidate refused, exposing the ruse, and Dawid ended the call. Later frame analysis showed the synthetic face closely resembled Polish politician Sławomir Mentzen. Vidoc's postmortem noted both personas shared a similarly strong, Asian-sounding vocal accent despite claiming different nationalities (Polish vs. Serbian), and that the second persona's answers felt over-rehearsed, as if the operator had already been through Vidoc's specific interview sequence before; this was the basis for the company's suspicion that one operator (or coordinated group) ran both personas, and possibly many more against other employers.
Lure: two well-groomed fake personas, "Makary Krol" (claimed Polish, Warsaw University of Technology grad) and "Bratislav Rakočević" (claimed Serbian), each backed by a convincing CV, an active LinkedIn profile with real mutual connections, and strong-to-exceptional live coding performance, including being the fastest candidate ever to finish Vidoc's full 2-hour timed coding interview. The second persona had spent weeks building LinkedIn rapport with the cofounders before any role was even open. Tell: in case 1, the candidate claiming Polish nationality/education could not speak a word of Polish, and his biographical answers (timezone, past employers, schooling) didn't hold together under casual conversational questioning in the non-technical final round. In case 2, the interviewer noticed an artificial-looking face mismatched to the LinkedIn photo, ChatGPT-style scripted answers, and audio/video lag; when directly asked to place a hand in front of his face, a simple test that breaks real-time face-swap filters, the candidate refused, immediately exposing the deception. Vidoc also flagged the second persona's oddly overconfident, seemingly pre-rehearsed answers as if he'd already been through this exact interview flow, feeding the suspicion both personas were run by the same operator.
Neither impostor was hired or paid. The first candidate ("Makary Krol") was quietly rejected after the final interview raised unresolvable doubts, but the encounter was not recorded, leaving Vidoc with only notes. The second candidate ("Bratislav Rakočević") was caught on a recorded call after refusing a hand-over-face liveness test; cofounder Dawid Moczadło ended the interview and later published the recording publicly. Vidoc added a mandatory in-person (or strictly ID-verified, filter-free) final interview round to its hiring process, published a free ebook titled "Deepfake Fraud Prevention: 17 Practical Strategies to Detect Fake IT Workers" (title confirmed directly on Vidoc's own blog post) on detecting fake IT workers, and went public with both incidents via a company blog postmortem (2025-03-27) and a Pragmatic Engineer newsletter deep-dive (2025-03-11) based on an interview with Moczadło. Vidoc reported being contacted afterward by dozens of other startups and larger tech firms describing similar experiences, some only discovering the deception after already hiring the person, suggesting a widespread, possibly coordinated campaign rather than an isolated incident.
This is one of the earliest and most thoroughly documented first-party case studies of real-time deepfake video filters being used offensively against a company's own hiring process, rather than against a bank or help-desk. It demonstrates that a candidate can pass CV screening, an HR screen, and even a rigorous, timed technical coding assessment while wearing an AI-generated face, meaning technical competence alone is not proof of identity, and that standard video-interview trust assumptions (a face on screen, an accent, a claimed home country) can all be faked concurrently. It also surfaces the broader pattern, echoed by dozens of companies who contacted Vidoc afterward and independently reported in the West in connection with fraudulent North Korean overseas IT-worker schemes, that fully remote hiring pipelines at software companies are being probed at scale by fraudulent-identity operators, with security/access-sensitive employers (like a code-security startup) especially high-value targets if a fake hire succeeds.
Vidoc's and Pragmatic Engineer's recommended/adopted mitigations: (1) require candidates to disable all video filters/backgrounds and verify this visually at interview start; (2) record all interviews, including early screening calls, to preserve evidence and allow frame-by-frame review; (3) use an active "liveness" challenge mid-interview, e.g., asking the candidate to place a hand in front of part of their face, which breaks most real-time face-swap filters because the algorithm cannot render the occlusion correctly; (4) cross-check claimed nationality/background against basic cultural and language fluency (e.g., ask a claimed native speaker to answer in that language); (5) verify timezone, previous-employer, and biographical details for internal consistency; (6) add a mandatory in-person (or at minimum, live unfiltered, ID-verified) final round before extending any offer, which Vidoc adopted after these incidents; (7) require formal ID/notarized identity verification prior to onboarding, especially for full-remote hires; (8) treat unusually fast/flawless completion of timed technical assessments combined with weak conversational depth as a correlated red flag rather than assessing coding and communication independently. Vidoc later published a free ebook titled "Deepfake Fraud Prevention: 17 Practical Strategies to Detect Fake IT Workers," confirmed directly on the company's own blog post, based on this experience.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology…