Talview Podcast

Inside the Gen AI Fraud Playbook Targeting Tech Roles | Global Interview Security Summit 2026 | IT Focus | India Edition

Talview - Global Interview Security Summit Season 3 Episode 4

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 30:26

In this session, you will explore how virtual recruitment has transformed technical hiring into a complex threat surface where bad actors leverage AI earpieces, screen mirroring, and parallel devices to fake knowledge. The panel examines the severe organizational repercussions of these malpractices, including client SLA breaches, repeated hiring costs, and critical insider threats to data security. Discover why generic technical assessments fall short and how evaluating real-time troubleshooting scenarios effectively filters out dishonest applicants. Finally, learn about a robust "hire till initial engagement" framework that incorporates national ID verification, continuous facial recognition, and post-onboarding performance tracking. 

Panel details:


Prabhanjan Prasoon (Birlasoft)
Yogesh Luthra (Atain)
Varun Khanna (Talview)

SPEAKER_00

Hey, good afternoon and welcome. Um let me let me just start with a story that probably isn't a story anymore. Uh but something we face and hear on a daily basis. I'm sure you also hear it every day. Candidate applies. Brilliant resume. They sail through the assessment, impressive on every interview round. The articulation is great, technically sound, exactly what the business is looking for. You as talent leaders say, yes, we've hit the nail. The offer goes out, and on day one, someone walks in who is not the person you interviewed. Quite common to hear. It's it's it's not it's not something which is um similar to the person who's just come in, but somebody who's a completely different human being, a little more rusty. Initially, for years, this has basically been a screen share problem. But today it's an second devices running in parallel. We are having AI earpieces feeding answers in real time. The fraud didn't disappear when the hiring went virtual. I'm sure you can resonate to all of this. And to be really honest, this has aimed and grown a lot when it comes to tech roles, right? Because that's where the access and the leverage is. So here's the uncomfortable truth that we are all gonna sit for the next 30 minutes. Virtual hiring is the default now. We're not going back. We all know that. The question is no longer how do we stop this? But it's it's it's it's got to do more about with um, I would say what's the trust? How do we build that trust which will survive the scale? And that's why we we got together with you all to understand uh and have your perspective around this is what's going on inside the Gen AI fraud playbook, and just as importantly, inside the defense playbook. So um this is this is this is just what we wanted to connect and talk to you about. And um I could not have asked uh for people more sharper than you all on the on the panel, right? Um fortunately, unfortunately, uh we were fortunate that we had three leading TA heads talking about it, but unfortunately, uh one of them uh had to um drop off at the last moment because of certain priorities coming at our end. So uh we apologize uh for that. Some things are beyond our control. So great. Uh it's it's it's it's actually great uh to have uh Pravanjan, you, and Yogesh today. So Prabanjan, uh you've been heading talent acquisition at BirlaSoft, spent almost two decades building talent strategies that scale and transform. You've been running high-volume hirings, lateral campus, strategic resourcing, leadership recruitments across geographies. You've been living at the intersection of people inside data and HR technology. Exactly the toolkit this problem demands. Yukesh, uh, you've been leading the talent acquisition at Atane, and you bring over 17 years of uh global talent acquisition across IT, sales, leadership hiring in markets all over the world. Anyone better cannot understand the real tension which exists between hiring fast and hiring right. I'm sure you will have insights around this where velocity and integrity collide. So uh that's that's that's what we wanted to uh talk about. Uh we we we are all talking about one shared challenge here: protecting the integrity of the hire in an age where the candidate on the screen may not be the candidate at all. So it'll be great uh to hear from y'all around these challenges, which you must be hearing uh day in, day out, facing day in, day out in your organizations as well. Um we all know that proxy fraud is in new right now. Screen sharing, second devices running in parallel, AI earpieces feeding answers. Because what this actually is leading to is the difference of the candidate who applied, passed the assessment, and cleared every round is not actually the person joining on day one. It would be great to have your thoughts uh around the same. Over to you all, please.

SPEAKER_01

So uh first of all, thank you very much, Warul. Uh I think you opened up so well. And I'm really excited to you know uh think about certain scenarios in my mind, you know, when you were talking about that how we had faced it earlier, and typically in post-COVID era, uh in uh in starting in 2021 and 2022, it was at its peak. And uh uh definitely every day we used to find a new way of uh you know a fraudulent case coming in, uh, impersonation was its uh all high time peak. Um, you know, whatever you have said, I could you know relate to. Uh but but you know, I think uh what is more important for an organization is how much uh I would say resilient you become in terms of you know these situations and you become more and more robust processes and toolkits. So we tried, you know, um, and uh you know just to start with, uh I remember a case uh in uh 2022 when I was in my previous organization. So Birlausoft, I have joined last year. Before that, I was with Soprasteria. I remember in 2022, uh one day one of the delivery heads literally he was he was running to me, came running to me and said, uh, we are in a very, very critical situation. Um and you have to help us. I said, what happened? And then uh once I spoke to him, what what we discovered, you know, there was a senior Pope, you know, I I would, you know, he was an architect level, whom we had hired. And uh, you know, it was a high stake uh requirement, and we had also discussed with customers, uh, and and customers was expecting this person, and they had also some dependencies, and you know, a lot of uh deliverables were aligned to this person. Uh and the person joined, and he was not the person who was interviewed and you know got through the different uh level of interactions and all. And this person was uh actually was knowing nothing in terms of uh what was expected. So the credibility was almost broken from uh you know from the customer perspective and then customer-to-customer perspective and everything. And then we we started thinking, uh, what shall we do? You know, how to uh you know handle these kind of situations. Although we had already brought a lot of uh stringent processes. For example, if somebody's uh you know coming for a an interview, uh national ID-based validation we had brought in, you know, uh screen capturing. Uh we were very vigilant in terms of uh you know bringing those proctored uh involvement of you know assessment. Uh then uh we tried for personal interviews, but unfortunately in that case, there was no personal interview happened because that person was not available in that particular town. So, in spite of bringing whatever we could do, still uh you know, we were facing those kind of issues. So ultimately, uh you know um what we have done is uh at least uh if you ask me, uh you know, this problem has uh a great solution until somebody brings in a new uh you know way of uh uh going out of it. So one thing what we brought is we brought an proctored assessment, uh national ID-based uh checks in the beginning. So a person coming in, the the validation is happening based on the national ID of that individual, then the same person is moving to L1, then again in L1 interview, the the facial uh recognition based uh you know uh match is happening. Then in L2, the same data flows, the system again tracks and you know matches, and uh uh then towards the end, when the person comes for the joining again, the same thing happens, you know, based on this facial recognition. It is being checked that whether the resumer which came in, the person who was assessed on on uh you know bot enabled interview, then L1, then L2, then at the time of joining, is everything matching or not? And then uh um, you know, during the proctored enabled assessments, also we had uh checked. In fact, we have put a lot of uh uh you know strong validation in terms of flagging. So whenever somebody is even uh uh you know, I would say not a severe uh deflection, but even a small deflection is is catching as a uh flag over there. So we used to go and and check uh as per the timestamp there, how that person is doing. So uh we tried to bring uh you know a lot of uh uh things at different stages so that uh such kind of fraudulent cases can be avoided. But uh uh you know the most I would say difficult thing is like you said, uh you never know whether a screen is being shared, right? And in many proctored environment, you know, uh system is not able to catch that, whether the screen is being shared. And uh uh uh but there are certain platforms which are catching it up. So I think I have a lot more to share and talk, but I think let's hear from Yoges, and then uh uh you know probably you can go back.

SPEAKER_02

Thanks, thanks, Prasul. So I think they there are two different things. One is forging the interview, another is the person who is giving the interview, and the completely different person who is joining on the day one. So in my experience, the problem that the completely different person is joining on the day one is it's uh decade old problem and it's it's been happening for for a good time. And of course, I also had to face you know uh similar kind of situation, situations where uh there was an interview with us, but the person was supposed to join at the client location. So the person thought that nobody will come to know that who gave the interview and who joined at the client location, and the completely different person uh joined there. Fortunately, fortunately, uh one of our representatives was there at the customer location, and we found that the person is not the same, and we uh took a proactive uh uh uh step and informed the client that there is something uh fishy and we want to investigate it. But now uh uh I'll be true here. We are not facing this issue. The issue we are facing is forging the interview. The person is the same who is giving the interview and the who is joining, but uh there is a gap in the knowledge of the person because there was screen share and a lot of this. This is the real-time challenge now because of the AI and the screen sharing, and a lot of different tech uh tech platforms available. So, as person is uh very right that uh you cannot completely check that uh if the screen is being shared because still platforms are evolving. So, our take that what we are doing, we are trying to do technical assessment more on the troubleshooting side to check the real-time scenario so that uh it's not easy to it's not the generic uh you know, the technical assessment that person can think of and can prepare of and can do some multiple you know uh platforms available to give the answer. So, our our our intent is to give get some real-time troubleshooting type kind of you know uh situation where it is required to be you know thinking in the problem rather than just you know googling out or getting the information from some AI tool. So that's how we are able to filter the crowd, which uh is you know faking the knowledge uh they are having. In fact, the person who is giving the intuitive is not that they are completely they don't know anything, the problem is they have little knowledge, but they are showing that they aren't working on the tools which recently came in the picture. So a lot of you know, in fact, things starting from the uh uh uh resume screening only. So there is definitely a lot of mistakes, like it's the saying if uh there is always a you know uh sign behind it. So if if you screen the resume, you will get to know the uh the candidate is saying that he or she has experience from five years, but the skill is existing from the last two years. So these are these are kind of the things, you know, which of course, with with the help of the latest platforms that we are using with uh the you know human assistance that we are doing. So our problem is faking the knowledge, not exactly you know, joining the completely different platform uh person, and we are trying to solve it with uh latest platforms.

SPEAKER_00

Absolutely. Uh, I think two things very evidently came out from what you both said. Obviously, we are all aware about defake, AI assisted identity fraud, proxy interview, because these these have great repercussions. That's what we've all heard from businesses. What happens is one, obviously, you have uh client SLA breaches which are happening. Uh, there is higher early attrition which is happening and which is leading to repeated hiring costs as well, right? And and the biggest is the what what what we have heard from clients across the globe is that insider threat and data security exposure. That's another one which is very critical considering the kind of business uh in which you are operating with your data as well as your clients' data as well. So uh we we we all agree and we all uh we all know that and we have all uh uh accepted that virtual hiring is gonna be the default right now, right? We're not going back. So and and we all know that um it's usually the technical assessment stage where the maximum uh malpractices happen. So it'll be great to hear from you both. What specific controls do you want to take or have been taking or have been hearing which forced you to take those uh steps? Uh, and how have you been seeing it getting better and getting caught at the right stages as well?

SPEAKER_01

So uh I think uh very uh I would say apt question, Varunt. So typically, you know, I think uh like Yogias was talking about, it starts from the resume. I think uh more and more authenticity is missing in the resumes nowadays. You know, let me be very honest with you. And that is why uh so what we have done is uh we have first brought, you know, I think AI enabled uh screening. Now the the problem with AI-enabled screening is uh all the resumes are coming with you know fantastic information being fed in that particular resume, which is almost 200% matching to the CV. Sorry, to the JD. So it will pass the screening, right? And uh so actually, AI-enabled screening, I don't take it as a real screening. You know, it's just since we have to do it, we are doing it. Let me very honest with you. It's a tick in the box, but we are not getting the right kind of results. Then we have bought uh the next uh screening, which is one-way interview, wherein a bot is taking uh around 25 to 30 minutes of interview of that individual, wherein uh initial screening is happening on the technology part, uh, little deep dive, uh not not uh I would say a deeper kind of an interview, but you know, a high-level uh kind of a screening process. That I consider as one of the you know effective ways of screening the resume. So once we and and let me tell you, today if we you know put 100 uh post AI screen resume for bot interview, uh typically 30 to 35 percent we are getting as you know good to go. Uh and and that to when we are uh uh putting a threshold of uh you know uh close to 70 percent, right? So uh 72-75 percent. So I think uh you know, once we get that, then we you know get into uh you know the the the virtual interview process, and that's where uh uh the the AI enabled proctoring is helping us. And like I was telling uh you know a few minutes ago, uh it's helping us and it's helping us up to a great extent, no doubt about it. But still, you know, uh we feel that we are not able to put control on certain things. Uh, specifically, you know, recently what I have heard is uh you know, one person did some did something, you know, we don't know how he did it, but that person did something, and uh you know, somebody else was uh in fact, the screen mirroring kind of thing was happening, and somebody else was uh talking over there uh to this particular person, and he was having some microchip or something, and then he was speaking about it. Uh so this is all how he did it, in spite of having a great proctoring uh platform. Uh, even the you know, we have gone through the the recording for multiple times, but at least I could not able to understand that how this person has done it. It was as real as you know you can imagine. So I don't know you know how how to put control on these things, like Yogis was also telling that tools are evolving, you know, such. So uh I am also uh expecting that something better will come. But yeah, we are able to control it up to a great extent. Uh with so three things. One is I think AI-enabled screening is is it is uh I would say a pretty generic thing, but you know, bot-enabled one-way interview is helping us a lot, and then on top of it, uh uh you know, AI-enabled proctored virtual interview, human interview, virtual human interview. And I think it's important to uh talk about human nowadays. So the human interview, it's a two-way interview, and uh so uh we are bringing a lot of control there. And after that, uh, if uh if we are hiring up to a certain level, we still insist those to come to office and have a face-to-face meeting because you see, nothing can uh you know replace uh you know a face-to-face interaction at least towards the end. Uh, it's very important to understand sometimes. So we are also trying to push for certain level and above. Uh, of course, at a junior level we try to let go, uh, but we wish that we could you know do it for all the levels. So that's how you know we are trying to just bring all the controls in the system right now.

SPEAKER_02

You want to say something, Burut?

SPEAKER_00

No, no, I wanted to say, Yogesh, your thoughts. I'm sure you can resonate a lot with all of this, but I'm sure there'll be something else that you also have to add on.

SPEAKER_02

I mean, uh it's a similar kind of things. We are also evaluating the tools which can help us in sentiment check as well, which can bring in some information there, uh, along with that, you know, the national ID check, if uh, you know, specifically for few roles, sentiment checks, we get to know that you know how the where the you know the the entire interview is going. And of course, we also do uh the in-person interviews for some, you know, at least for the senior positions. Uh, but the problem is in in today's world the knowledge is very important, and uh we have to hire the people wherever they are. They are maybe in tier two, tier three cities where we don't have offices, and this is with every organization, and we have to hire them. And probably uh it is not possible to get the in-person interview for all of the locations. So, yes, uh uh you know, the virtual interviews to make them as real, as close to you know, uh in-person uh interaction, we try to do so. And uh, what I think the problem is not the people are using uh AI tools for cracking the interview, the problem is uh how smart the people actually are, because anyway, when they join, they will be using AI for their day-to-day work. The problem uh is they should know which tool to use, how to use uh which data should be used, the data should not be leaked. We cannot what data we cannot share, which kind of data we cannot share on which platform, it should be confidential. So, this is more important nowadays. I think the people definitely know the you know how to use the problem. The organization is are building their own AI tools. Uh the time it was taken earlier to write down a quote, or maybe four to five days, so it is being written in some couple of minutes. So eventually the organization. Are using it so uh uh to reject a candidate purely on the basis of to you know assumption that the person is not uh using some some tools, it's not uh uh uh authentic one, but it is important to understand uh uh the knowledge or kind of awareness that what should be used, where should be used, and which impact it is going to make for the organization, there should not be any threat for the data. These are the important things that we uh try to evaluate during the ether process.

SPEAKER_00

I I I just have one line to sum off everything that you guys said. I just picked it up. It's not it's not AI versus human. In the future, it's all about AI versus AI. Because since AI is getting evolved, it is the human which is required to actually validate which one is the real AI, right? Is it is it the candidate side or is it the other side? I think that's where the that's where the real challenge or where the real next thing is moving right now. That's what I personally feel as well. I know, um I know it's been almost two decades for you both in the industry and you guys have seen things evolve from what it was to where it is heading. Um my question to you is very clear and very straight. If you had to redesign the idle hiring integrity framework from scratch, what do you think would be some things that uh you would feel that these need to be fixed so that that leakage, if not completely closed, there can be some ways to fix uh the current challenges which are there and which are evolving every day.

SPEAKER_01

So uh let me start very quickly and I'll be very quick this time. Uh I think if you ask me, uh I am a strong believer of assessment. Uh assessment means uh especially tech assessment when we're hiring uh you know specifically for uh for our technical roles, and I'm a big fan of it. So if you if you ask me, you know, I will I will go as per how this Digiatra things happen. You know, a person's journey should start with facial recognition. You know, I the person enters to a platform, uh, you know, and with the facial recognition, the everything starts from there, you know, that matches with the national ID, and then you know, at every level when that person transfers, you know, the same uh, you know, the same information should happen. And an assessment should be must for every technical role, you know, up to a certain level. And uh I know there are a lot of platforms today which are providing an excellent way of you know technical assessment, you know, absolutely perfectly proctored and AI enabled, which is also giving a lot of uh you know insights and analytics out of it. Uh still it can be further evolved, but I think that can be added in between. And then uh you know, towards the end, when the person is joining, again, uh you know, a similar kind of you know facial recognition thing, which should be there. A person is joining. And then uh I will go beyond the joining also. We should also bring some some mechanism wherein we can track the person's engagement, performance for next at least three months, if not six months, but at least for next three months, and everything should be captured and and maintained through one platform end to end. So from uh I will not say hire to retire, but hire till the initial engagement, right? And then those information can be fed back to the system, which can also help us. Uh, for example, if we have hired a Java full stack person and the way the hiring has been done, the way feedback were given, uh, you know, based on multiple things, you know, and if the person is doing well in the organization in the initial three months, the same information can fed uh fed uh you know back to the tool and system, and then system can also learn based on that and provide that okay, this uh this way of hiring had helped, so probably uh you know you can go ahead and do this kind of uh assessment uh for the future hiring as well. So uh you know, in nuts, uh hire till initial engagement, you know, that's how I would like to go ahead with.

SPEAKER_02

So so uh what I think we are already going in that direction. It it's not the better where you know, I vote or b vote that how it should go. This will move in the direction where it is going. It is just a matter that when all of the all of these things get mature, and it is not only about the candidates, it is uh for the good of the organization as well. Because if you are using the right assessment tools, security tools, uh like uh national ID check and all, uh, on the one side, we are able at least to do some check, the candidate is channeled. On the other hand, this provides the standardization of the assessment, and the interviewer also able to uh you know check, you know, the assessments, the analytics after the assessments are detailed work, and there is no bias from the if if we are not using any uh standard tools or the standard assessment process, then of course sometimes uh maybe interviewer or person on the other side is not able to articulate that you know where is the gap or think in that direction. So this is helping the organization to hire the right person and to get the right uh you know uh uh what I'll say uh outcome out of the entire assessment. And of course, you know, the assessments that we are using for uh in a boat assisted uh interviews and all that also depends, you know, in which country we are using, what is the culture there. For example, the pickup rate uh for a boat call in India may be different than that in the Philippines, right? Or uh the person who is in doing the technical assessment uh and and uh more serious about it, maybe different uh kind of behavior in US as compared to India. So this will take you know from the global globalization point of view as well. That do we need to apply different tools for different countries that we are operating for, understanding about the culture and behavior there? So I don't think it's so far, but we are very close there when we will have all the things very finalized and things will be more matured.

SPEAKER_01

Yeah, I think uh just to add one point here, you have picked upon a very important aspect of uh you know uh the behavior and understanding of uh you know candidates and people of different countries. And uh uh one more thing which I've missed uh in my you know previous conversation when I was talking about the end-to-end system, I think one thing is also very important is you know giving a great experience to the candidate. Uh when we are talking about you know great candidate experience, uh you know, whether it could be through the processes, it could be through the tools, you know, uh whatever you know means we are bringing in, uh, you know, the candidate should be uh feeling great about the experience, whether he gets an offer, he gets into the system or not. But I think that feeling something which gets through, or he or she gets through, that is something amazing. So I think that will also be there in the in the mind when you know I'll think of you know designing anything end-to-end.

SPEAKER_00

Absolutely. Um, I thoroughly enjoyed uh getting a lot of insights from y'all. Uh I would have loved to have this conversation longer, but we definitely look forward to meeting y'all and get some more insights as well. So I really thank both of you for uh taking time out, uh, giving us insights from the experience that y'all have had and gathered. It it really it really resonates with what is happening in the industry. It's exactly what people are talking about. So I thank once again um for taking time out and um doing this with us. We really mean it really means a lot. Thank you very much.

SPEAKER_01

Thank you, Varun. Thanks for having us. Thank you. Thank you very much. Bye.