A voice-security firm interviewed a strong candidate for a senior engineering role, then noticed his face running half a beat behind his voice. A real-time deepfake. Eight days later the same fake identity applied again through a different recruiter. That's one side of the modern interview. On the other, the recruiter running the call might be the scam, quietly capturing your face and voice to open accounts in your name. Neither side is sure the other is real, and in ecommerce, where the job sits one step from payment systems and customer data, the stakes only climb.

For years the interview was the one part of hiring you couldn't really game. Resumes got embellished, portfolios borrowed, references coached. But the moment two people got on a call, things got honest. You were you, they were them, and the conversation sorted the rest out.
That's the part AI just broke. Not the resume screen, not the take-home. The live interview, the thing everyone treated as ground truth. In 2026 there's a real chance the person on the other end of the call isn't who they say they are, and it runs both directions. The candidate might be fake. So might the employer.
Gartner expects that by 2028, one in four job candidate profiles worldwide will be fake. Fake as in fabricated outright: a generated headshot, an invented work history, and increasingly a live deepfake that talks back on camera. In a survey of 3,000 candidates, 6% already copped to some form of interview fraud, either sitting in for someone else or having someone sit in for them.
This stopped being hypothetical a while ago. Pindrop, a voice-security firm, posted a senior backend engineering role and interviewed someone they later called "Ivan X." Strong resume, confident on camera. His expressions ran a half-beat behind his voice, and his connection traced to thousands of miles from where he said he was. It was a real-time deepfake. Eight days later the same identity reapplied through a different recruiter.
The most organized version of this is run by a government. The FBI has tied hundreds of US companies to North Korean operatives who used stolen identities and AI-touched photos to land remote roles, more than 300 of them through a single laptop-farm operation. KnowBe4, a security-awareness company of all places, hired one in 2024 who cleared four video interviews and a background check before anyone caught it. Amazon's security chief said the company blocked over 1,800 suspected North Korean applicants in roughly eighteen months, with attempts climbing every quarter.
You don't need a deepfake to fake an interview, though. The quieter and far more common version is a real person reading answers off a second screen. There are tools built for exactly that, overlaying suggested answers live while the interviewer talks. In one survey of hiring managers, roughly nine in ten said they'd hit answers they were sure came from an AI mid-call.
This bites harder in ecommerce than in most fields, and the reason is access. Tech roles already make up around 60% of deepfake hiring fraud. An ecommerce engineer touches payment flows, customer records, order data, admin credentials, so a fraudulent hire in that seat gets exactly what they came for: a remote, trusted position one step from money and data. For a store or an agency, that fake candidate is closer to someone applying for keys to the checkout than to an HR headache.
Now turn the camera around, because job seekers are getting hit at least as hard.
Reported losses from job scams climbed from $90 million in 2020 to over $500 million by 2024, per the FTC, and since most fraud never gets reported, the real figure is bigger. The FBI logged around 20,000 employment-fraud complaints in a single year, close to quadruple the year before.
A few years ago the giveaway was bad grammar and a generic template. Now a scammer stands up a whole company website, a careers page cloned from a real Greenhouse or Lever listing, and a recruiter profile impersonating an actual person at an actual firm. The first message quotes your own career history back at you, because it scraped your profile to write itself.
Then the interview becomes the attack. A few of the shapes it takes:
The thread running through all of it: real hiring doesn't start on WhatsApp or Telegram, doesn't pay in crypto, and doesn't need your sensitive personal data before there's a signed offer on the table. A legitimate recruiter will survive you slowing down to check.
Put the two sides together and you get the odd reality of hiring in 2026: a video interview where neither person is fully sure the other is real. The candidate studies the recruiter's face for lag. The recruiter studies the candidate's for the same thing.
The fix has been almost funny in how old-fashioned it is. Google, Cisco, and McKinsey put in-person rounds back on the table specifically to beat fraud, and a large majority of recruiting leaders now say they run at least one in-person step for the same reason. After a decade of hiring going remote-first, the most reliable identity check anyone has found is being in the same room.
For ecommerce, which runs on distributed, remote, frequently cross-border teams, that's a real tax. The honest remote candidate in another country now carries suspicion they did nothing to earn, and the small store hiring its first developer has to budget for verification it never planned on. The open remote market that let an engineer in Kraków, Poland build for a brand in Austin, Texas is the exact thing the fraud exploits, which makes it the exact thing the new caution squeezes.
If you're interviewing for a role:
If you're the one hiring, you're really checking two things: that the person is who they say, and that they're the one answering. Layer for both.
woocommerce_before_shopify_load hook. There's no such thing, and a real engineer laughs, because WooCommerce and Shopify are rival platforms that don't load each other. An AI answering for them just pattern-matches the hook-shaped name and writes a confident how-to, because that's what it does when it doesn't know. Make the premise impossible, not merely obscure, or you punish an honest "I'd have to check." The trick fades as it spreads, so read it as a signal, not a verdict.Verification, not paranoia. Confirm the human, then get back to the actual conversation.
There's one principle under all of these checks, and it turns up somewhere odd: analog clocks. Ask almost any AI image generator to draw one at 4:30 and it hands you 10:10 instead, again and again, because nearly every watch photo it trained on is set to 10:10. It never learned what a clock is, only what clock pictures tend to look like. Good human checks aim at that same seam. You're not quizzing for knowledge, you're pointing at the spot where the model pattern-matches instead of reasons: an impossible premise, a detail too recent or too specific to have been in the training data, a conversational turn nobody scripted. Those gaps close as the models improve, so the work is finding the ones still open.
None of this fully closes the gap, and the reason is uncomfortable: the detection tools and the fakes are built on the same models, so better cameras and liveness checks and deepfake detectors keep getting matched by better fakes. The one defense that doesn't lose that race is the oldest one, being in the same room, or checking an identity against something the video feed can't reach. An industry that spent ten years proving you never have to meet anyone to work together is quietly admitting there's still one moment where you do. Nobody loves that as the answer. For now it's the one the fakes can't follow you into.
ARTICLEThe developer who ditched Magento for Shopify last year is now applicant four hundred for one remote opening. A Magento ...
ARTICLEThe rote whiteboard ritual is dying, but the thinking it tested matters more than ever. What ecommerce engineers should ...
ARTICLEWhat WooCommerce, Magento, Medusa, and Shopify hiring managers actually check on your GitHub, why the contribution graph...
// POST A ROLE · LIVE IN 5 MIN