Time to Hire
Welcome to "Time to Hire," a dynamic and insightful podcast created by the Recruitment Process Outsourcing Association (RPOA) specifically for talent acquisition professionals to keep them well-informed about the latest industry trends and best practices.
In each episode, RPOA Executive Director, Lamees Abourahma, hosts prodigious talent leaders to share talent market intelligence and innovative recruitment approaches. Tune in to the podcast to help you enhance your hiring processes, strengthen your employer brand, and innovate your talent strategy.
Whether you're a seasoned talent acquisition professional or just starting in the field, "Time to Hire" provides an invaluable platform to expand your knowledge, learn from industry leaders, and stay up-to-date with the rapidly changing world of recruitment.
Time to Hire
One in Four Applicants Could Be Fake: Identity Fraud in Hiring with Matt Moynahan
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Applicant fraud has evolved from resume embellishment into a sophisticated, AI-enabled threat — and the hiring process is now a primary attack vector. According to Gartner, by 2028, 25% of all job applicants could be fake, and a Get Real Security study found that 41% of enterprises have already unknowingly hired a physical imposter. Nation states, criminal organizations, and coordinated fraud rings are using AI to infiltrate organizations through the front door — exploiting the very digital hiring processes that enable modern talent acquisition at scale.
How can talent acquisition and RPO leaders protect the integrity of the hiring process without disrupting the candidate experience — and what role should technology play? In this episode of Time to Hire, host Lamees Abourahma talks with Matt Moynahan, CEO of Get Real Security and RPOA Silver Partner, about what applicant fraud actually looks like today, how to layer human and technology-based defenses across the talent funnel, and why this moment is a strategic opportunity for TA leaders to partner with cybersecurity and redefine the function.
Follow GetReal Security on LinkedIn
About the Podcast
Time to Hire is produced by the Recruitment Process Outsourcing Association (RPOA), the leading authority on recruitment process outsourcing (RPO) foresight and innovation, and the trusted convener for the global RPO community. Through conversations with industry leaders, the podcast explores the trends, insights, and innovations shaping the future of talent acquisition.
Learn more about RPOA and join the community at: https://www.rpoassociation.org.
Follow the host, Lamees Abourahma, on LinkedIn.
Introduction: The Scale of Applicant Fraud
Lamees Abourahma: [00:09]
Imagine you have just completed a rigorous hiring process. The candidate interviewed well, passed your skills assessment, cleared the background check, and accepted the offer. Weeks later, you discover the person who showed up to work is not the person you hired — and the individual who interviewed for the role never existed at all.
This is not a hypothetical. It is happening right now at scale across industries. According to Gartner, 62% of organizations have experienced a deepfake attack in the past 12 months, and a separate Gartner projection warns that by 2028, 25% of all job applicants could be fake — that's one in four. A new study from Get Real Security found that 41% of enterprises surveyed unknowingly hired a physical imposter.
For talent acquisition and RPO leaders, the implications are direct and significant. Today on Time to Hire, we are getting into the details of what applicant fraud actually looks like, why it is getting harder to detect, and what organizations can do about it — from human-centered interview practices to AI-powered detection technology.
I'm Lamees Abourahma, host of the podcast. My guest today is Matt Moynahan, CEO of Get Real Security, and a seasoned cybersecurity executive with more than two decades of experience leading global technology companies. Matt previously served as CEO of OneSpan, a publicly traded cybersecurity firm, and Forcepoint, where he led a successful shift to cloud-native models. Get Real Security is also a new RPOA Silver Partner, bringing together digital forensics, cybersecurity, and artificial intelligence to help organizations defend against a new generation of identity-based threats. Welcome, Matt.
Matt Moynahan: [02:26]
Thank you. Great to be here.
Defining the Threat: Who Is Behind Applicant Fraud?
Lamees Abourahma: [02:27]
We're talking about applicant fraud today, and it's not a new problem — but deepfakes have changed the threat landscape significantly. From your vantage point, how serious is the problem right now, particularly for talent acquisition leaders?
Matt Moynahan: [02:46]
It's a really significant problem. It's in the news everywhere, but I don't think the gravity of it has fully sunk in yet.
I was talking to a talent executive at a Fortune 100 company recently. She said they were getting flooded with fake resumes, and she wasn't sure what was going on. I asked her a few questions: Did good people suddenly turn bad? No. Did the company do anything differently year over year to deserve this flood of applications? No. Are good people just creating fake resumes thinking they'll never get caught? She didn't think so.
And that's because these aren't regular applicants making questionable choices. These are criminals trying to get into your company — nation states, threat actors. They are using AI to scale, and it's a very big issue. This isn't just about fake candidates. It's really about enterprises being under attack, and the human capital supply chain being under attack — much like the software supply chain was under attack for the past two to three decades. And it can now be executed at machine speed with AI.
Lamees Abourahma: [04:18]
That story really illustrates the shift — we're not talking about applicants embellishing credentials. We're talking about a fundamentally new threat: AI-assisted resume fabrication, state-sponsored infiltration. Walk us through the threat landscape. What are the most common forms you're seeing, and which pose the greatest risk?
Matt Moynahan: [05:04]
There are really three types of threats — two of which are particularly dangerous.
At the most serious end is nation states. Years ago, I was CEO of Forcepoint, which focused on insider threat. Foreign governments would recruit PhDs to infiltrate companies — industries with scarce, specialized talent, like pharmaceuticals, where many foreign nationals participate legitimately in the global workforce. That created an obvious vulnerability. North Korea has perfected the mass-market version of this. They trained up a highly skilled IT workforce. These aren't bad workers — they're quite good. And that's what makes them so dangerous.
The second category is criminal organizations, attacking companies for various reasons.
The third is employment fraud by individuals — people holding two or three jobs simultaneously, using AI to meet baseline performance expectations at each. We saw an uptick in this during and after COVID.
All three are serious, and they sit on a continuum: from nation states and criminal organizations seeking data theft and other assets, to individuals trying to supplement their income by holding multiple positions. What they share is sophistication and scale. These adversaries aren't applying to one job — they're applying for 20 or 30 at a time, using different identities. The average person using AI to polish a resume is a top-of-funnel concern. The adversaries getting through the middle and bottom of the funnel and into your company are a fundamentally different category of risk.
Target Industries and Insider Threat Scope
Lamees Abourahma: [08:12]
Are there specific industries or roles where the stakes are highest?
Matt Moynahan: [08:20]
It's fairly broad-based. Historically, state-sponsored infiltration was focused on high-IP environments — stealing chemical compound formulas, pharmaceutical research, aircraft or vehicle designs. That type of intellectual property theft is costly and targeted.
Now it's happening across the board. I routinely hear from small AI companies being targeted by fake candidates trying to steal their algorithms. Anything of value is at risk. The Global 2000 are obvious targets because they hire at scale — it's easy to lose a needle in the haystack in a global matrix organization. But these adversaries are also going after very specific intellectual property in mid-market and smaller companies, depending on what those companies are building.
Lamees Abourahma: [09:45]
I'll add something I heard from Rachel Wilson, Chief Data Officer at Morgan Stanley and a former National Security Agency executive. She made the same point you did about banks being targeted by North Korea and Russia — not just for intellectual property, but to steal money to fund their regimes. North Korea has generated billions this way.
Matt Moynahan: [10:25]
Staggering. And in some of these cases, you're actually violating employment laws by hiring these individuals, depending on the jurisdiction, because the use of proceeds funds an adversarial regime. It's a double exposure.
North Korea perfected the concept of gaining privileged access to IT systems. When they get those privileged positions, there's a ripple effect. Not only are they funneling paychecks back to the regime, but once they're identified and at risk of exposure, they often steal information on their way out — because they already have access to accounts and systems.
Human-Centered Detection: What Recruiters Can Do Now
Lamees Abourahma: [11:12]
Many organizations are still approaching this at the human level — things recruiters can do during the interview process. What can organizations adopt at that level, before turning to technology?
Matt Moynahan: [12:26]
When new threats emerge, the first instinct is to put human controls in place. Early on, when deepfakes first appeared, interviewers would ask candidates to hold up five fingers in front of their face — which was reasonably effective when the technology wasn't that sophisticated. It doesn't work anymore with a quality deepfake.
I've heard about increasingly elaborate workarounds: asking a European candidate to hold their phone next to the wall socket to prove it's a European plug, or checking the time zone displayed on their phone. These controls escalate from mildly intrusive to outright absurd — and you're forgetting that you're trying to hire someone. You're in a competitive talent market. Security controls matter, but not to the point where they create a farcical experience for real candidates. Every hurdle you ask someone to clear reflects your employer brand.
We've reached a point where we need to start turning more seriously to technology. Human controls are unevenly applied — they depend entirely on the sophistication of the individual interviewer. To address a threat this serious, you need a rinse-and-repeat process. That consistency requires technology.
Lamees Abourahma: [14:37]
So having at least some standards in place is a starting point — even for organizations that are earlier in their thinking on this. But given the sophistication of these threats, how does technology take it to the next level?
Technology Solutions: Funnel-Aware Detection
Matt Moynahan: [15:34]
It really depends on where you are in the talent acquisition funnel.
Where Get Real Security focuses is the mid and lower funnel — the candidates who have already passed initial screening and skills assessments. That's where you need to be certain you're not dealing with an adversary. Remember, sophisticated actors will often pass your top-of-funnel filters. They're good at what they do.
Technology at the top of funnel should focus on anomaly detection: identifying patterns that signal fraud at scale — like multiple resumes linking back to the same individual applying under different identities. If you have 1,000 new resumes and you're not checking whether any of them share phone numbers, mailing addresses, or other identity markers, you're missing obvious signals. Applying to 20 or 30 jobs with different identities is a known tactic. Technology can surface those anomalies cost-effectively, before you spend money on background checks on every applicant.
As you move into the mid and lower funnel — candidates you're seriously considering — the threat profile shifts. It could be a deepfake used during a live coding interview, or a physical imposter using a fabricated identity. At that stage, what matters most is identity consistency: Is the person showing up in this video call the same person who appeared in every prior interaction with your company? Are the digital identity attributes — name, email, phone number, mailing address — consistent, and are they unique to this applicant?
Proxy farms are a common tactic. North Korean operatives, for example, frequently share mailing addresses and US phone numbers across multiple candidates. If ten people are applying using the same mailing address or phone number, that's a signal most organizations aren't currently checking for.
The core question at that stage: Is the person appearing in pixels and sound waves in front of you the same person, every single time?
Lamees Abourahma: [19:30]
And if I understand correctly, your technology isn't limited to the hiring process — you also apply it to existing employees?
Continuous Verification: Beyond the Hire
Matt Moynahan: [19:45]
Exactly. It's two sides of the same coin.
When you're engaging with an unknown candidate, you're assessing risk up to the point where they become a known employee. But many companies continue using the technology after hire to protect all employees from impersonation. The underlying question is the same every time: Is the person I'm speaking with a real human being, or are they synthetic?
A real human being sitting in a real environment — with light, shadows, physical geometry — produces a digital representation that has characteristics a deepfake doesn't replicate when you know what to look for. Our technology asks: Is this real or synthetic? And if it's real, is it the person you think it is? Have you seen this person before?
Think of it as TSA PreCheck or Global Entry for every phone call and every video session. Global Entry looks at your face, matches it against your passport, and clears you. This applies that same logic on a continuous basis: every phone call, every video interaction, every time. It's not surveillance — it's pattern matching that confirms yes, this is the same person.
If someone were to outsource their work, or have a third party show up to a meeting in their place, we would know that. That matters because impersonation attacks are a very real threat to employees — attackers steal their identity to gain access to corporate systems.
The MGM and Marks & Spencer incidents are a prime example. A group called Scattered Spider researched employees on LinkedIn, gathered their personal information, and called the IT help desk claiming to have lost a device and needing a password reset. No AI-generated voice. Just social engineering. That attack cost MGM roughly $100 million — and it was straightforward impersonation. When faces and voices appear consistently in video and phone interactions, you can verify identity continuously, not just once.
The Strategic Opportunity for RPO and TA Leaders
Lamees Abourahma: [23:37]
Our audience on Time to Hire is specifically talent acquisition and RPO leaders — professionals who sit at the center of the hiring process for large organizations. What's your message directly to them?
Matt Moynahan: [24:03]
I think this is a defining opportunity for RPO and talent acquisition leaders to deliver a genuinely strategic service.
HR has historically not always had the strongest internal profile in organizations — often associated with benefits administration rather than business strategy. That's changing, and the human capital function is becoming increasingly critical. What you're seeing now, for the first time, is security executives and RPO and TA leaders having to partner to protect the assets coming in through the front door.
Cybersecurity has spent 30 years defending the back door — monitoring networks, securing systems. Now the threat is walking in on two legs through the front door, and talent acquisition is the function that controls that entry point. This is a real opportunity for TA to take this threat seriously, build the brand of the function internally, and develop a genuine partnership with identity and security teams. It's a leadership role, and it requires collaboration across functions that haven't traditionally worked together closely.
The Future of Hiring in a Zero-Trust World
Lamees Abourahma: [25:32]
Looking ahead — Gartner projects 25% of job applicants could be fake by 2028. If those projections hold, what does hiring look like in five years, and how do organizations build trust in a process where identity itself is in question?
Matt Moynahan: [26:14]
The starting point is simple: you can't blindly trust anymore.
There's already more fake content in circulation than real content. AI is producing material — images, video, audio, text — faster than any human or human organization could. When Steve Jobs launched the iPhone, it took relatively little time before iPhones were capturing more photos than all cameras combined throughout the entire history of photography. AI is doing something similar to content at large. Any current event now has more synthetic coverage than authentic coverage.
Given that reality, I would encourage organizations to move everyone through a digital hiring process — and not because in-person is inherently safer. Physical presence guarantees a body showed up. It doesn't guarantee the right person. Background checks have always been retrospective. North Korean operatives show up in person.
What digital processes enable is consistency tracking: you can verify that every interaction across every touchpoint in your organization connects back to the same individual. That's something you can't achieve when your hiring process is a patchwork of in-person, digital, and phone interactions spread across different teams.
The practical framework looks like this: don't trust blindly. Build a top-of-funnel filtering process to surface anomalies cost-effectively before spending on background checks. As candidates advance, apply progressively more rigorous identity verification at the mid and lower funnel. And make it continuous — not a one-time check. Most of the risk materializes after identity has been verified once. That's when the games start.
This threat is not going away. China is now replicating North Korea's model using Polish identities. The problem will scale. You cannot unwind digital transformation — which means this has to be solved, and solved in a way that doesn't require reverting to 100% in-person hiring. That's not economically viable, and it wouldn't even solve the problem.
Closing: Passion, Purpose, and Trust in a Digital World
Lamees Abourahma: [28:59]
Matt, I want to close with something more personal. You're clearly passionate about this issue. What drives you?
Matt Moynahan: [29:46]
It really comes down to trust.
I've been in cybersecurity for 30 years. Early in my career at Symantec, we had a tagline about trust and working in a digital world. But it wasn't really about trust back then — it was about getting basic security in place. Now we're actually at the trust problem.
AI is eroding trust quickly, and I think humans fundamentally crave authenticity. That's what Get Real Security's brand is built around — just keep it real. We've seen it with younger generations moving away from certain social platforms in search of something more genuine. I think businesses are now experiencing the same dynamic.
My motivation is to ensure the internet isn't just serving up dirty water. Whatever the tap is — your browser, your phone — the data flowing through it should be clean and trustworthy. The consequences of failing to solve this go well beyond talent acquisition. There are cases of AI-generated phone calls targeting parents, claiming their child has been kidnapped. The damage to human trust is profound.
Even if corporate America wanted to return to 100% physical interaction, it couldn't afford to. You can't unwind digital transformation. This problem has to be solved. That's what gets me out of bed every day.
Lamees Abourahma: [31:27]
I'm glad we can't unwind it — and I'm glad there are people like you committed to solving it. Thank you so much for joining us today, Matt. This has been a genuinely important conversation for our community.
Matt Moynahan: [31:50]
Thank you. The RPO community is really at the center of everything on this issue — they're the hub in the human capital supply chain. It's an exciting time to be in this profession.
Lamees Abourahma: [32:16]
I hope you enjoyed this episode of the Time to Hire podcast from the Recruitment Process Outsourcing Association. Give us a review wherever you listen, and always stay connected, stay engaged, and stay informed about what's happening in the talent and recruiting world by tuning in to RPOA — The Place to Go for RPO.