HR Hiring Simulations - Breacher.ai

HR Hiring Simulations

Every other route into your organization is reviewed by security. This one issues a laptop.

An authorized deepfake candidate simulation run against your real recruiting process. We build a synthetic applicant with a generated face, a cloned voice, and a coherent history, then submit it through screening, live video interview, reference and right to work checks, offer, and onboarding. You get a per-stage record of where verification held and where it did not. Runs externally, with nothing installed in your ATS.

Video Interview Candidate Identity Recruiter Vishing Reference Checks Offer & Onboarding Payroll Diversion

Built for security teams, talent acquisition leaders, and insider risk programs.

The hiring pipeline is now an attack surface

1 in 4
Candidate profiles worldwide projected to be fake by 2028
Source: Gartner, July 2025
6%
Of candidates admit to interview fraud, posing as someone else or having someone pose as them
Source: Gartner survey of 3,000 candidates, 2Q25
70 min
For an inexperienced researcher on a five year old computer to build a synthetic identity for video interviews
Source: Unit 42, Palo Alto Networks, 2025

Why hiring is the softest path in

Remote recruiting scaled to the point where a stranger on a video call became a normal hire.

The output of the process is access

Every other route to a credentialed identity runs through a security review. Hiring ends in a directory account, a device, a VPN profile, and a payroll record, and the decision is made by people whose performance is measured on time to fill.

Verification was never really there

Most pipelines treat the video call as the identity check. A face on a screen, a resume, and a reference contacted by email are not identity verification, and nothing downstream of the interview re-checks the assumption.

Detection advice ages badly

Recruiters are told to watch for lip sync drift or to ask the candidate to wave a hand across their face. Those tells close every generation cycle. The verification step does not, which is why we test the step rather than train the tell.

What we submit, and what it proves

Six stages of the hiring process. Run the full chain end to end, or scope to the stage you are least sure about.

Live Video Interview

A real time synthetic candidate on your actual interview call, in Teams, Zoom, or Meet. It answers questions, holds a conversation, and responds to challenge prompts. Tests whether an interviewer has any procedure at all for establishing that the person on screen is the person being hired.

Real-Time AvatarChallenge ResponsePanel Interview
Candidate Identity & Documents

Synthetic identity documents and a matching synthetic face submitted through your right to work, background, and screening vendors. Establishes whether the document check and the interview face are ever reconciled against each other, or simply filed in separate systems.

Right to WorkBackground ScreeningSynthetic Identity
Recruiter & Hiring Manager Vishing

A cloned voice calling into recruiting: a candidate chasing a decision, a hiring manager pushing to skip a check, an agency contact confirming a placement. Tests whether recruiting has a callback procedure, and whether urgency from a familiar voice is enough to move a stage forward without it.

Voice CloningCallback ProcedureAgency Impersonation
Reference & Credential Verification

Controlled references answering from attacker held contact details, and credentials that do not survive an independent check. Tests whether references are contacted through details the candidate supplied, and whether anyone verifies the referee rather than the reference.

Reference IntegrityCredential CheckEmployment History
Offer, Onboarding & Provisioning

The stage almost nobody tests. Offer acceptance, identity re-verification at day one, account provisioning, and equipment dispatch to a supplied address. Establishes whether onboarding ever re-checks the identity that interviewed, or simply inherits it.

Day One VerificationAccount ProvisioningEquipment Dispatch
Payroll & Bank Detail Change

A voice or message requesting a change of bank details on an existing employee record, or a new starter supplying details that do not match the identity on file. Tests the HR service desk and payroll approval chain, which is the same fraud path whether the requester is real or synthetic.

Payroll DiversionHR Service DeskOut-of-Band Verification

How the engagement runs

The hiring variant of OSES™, our orchestrated simulation framework. The synthetic candidate is the vehicle. The subject under test is the sequence of verification steps your process is supposed to apply between application and access.

01
Scope & Authorization
Requisitions in scope, stop line, named approvers in talent acquisition and security, and abort conditions agreed and signed before anything is generated
02
Persona Build
A synthetic candidate with a generated face, a cloned voice, a coherent history, and an online presence consistent with the role being targeted
03
Pipeline Submission
Application, screening call, live video interview, and verification checks run through the real recruiting path with the real people who staff it
04
Stage Analysis
Which stage advanced the candidate, which check was performed, which was skipped, and what would have had to happen for the process to stop it
05
Findings & Re-test
Per-stage findings, an OSES™ Score reported with the sector position, remediation aimed at the procedure that broke, and the same path run again

Every engagement runs under signed authorization against your own process, with agreed requisitions, a documented stop line, named approvers, and abort conditions. The default candidate is a fully synthetic persona, so no real individual is impersonated. Where a scenario requires cloning a named executive or employee, documented written consent from that individual is required before any asset is generated. Client names never appear in our public material. For the systems side of identity verification, see KYC penetration assessment, and for the voice channel on its own, AI vishing simulation.

Remote hiring, at volume

Organizations hiring people they will never meet, into roles that come with access worth having.

Technology & SaaS
Remote engineering hires with production access
Financial Services
Regulated roles and privileged systems
Managed IT & MSPs
One hire, many downstream client estates
Staffing & RPO
Placements carrying client liability
Public Sector & Defense
Clearance-adjacent and contractor pipelines

What makes this different

We run the chain, not the clip

A deepfake video played to a recruiter in a training session proves nothing about your process. We submit through the real pipeline and follow it to the stop line, because the failure is almost never the interview. It is the step after it that nobody owns.

Current-generation media

The persona is built with tooling available right now, on the same accessibility curve that put a working synthetic candidate inside 70 minutes of an inexperienced researcher's time. Not archived samples, and not a vendor demo reel.

Findings you can re-test

Every finding maps to a specific verification step, so remediation is a procedure change rather than a course assignment. Then the same path runs again and the delta is the number that goes to the board.

Common questions

What is an HR hiring simulation?

An authorized engagement in which a synthetic candidate is submitted through your real recruiting process, from application and screening through live video interview, verification checks, offer, and onboarding. The output is a per-stage record of where identity verification held and where it did not. It is a process test, not an awareness module for recruiters.

Why is hiring a security problem rather than an HR problem?

Because hiring is the only business process whose successful output is a credentialed insider with a laptop, a directory identity, and a payroll record. Every other access decision is reviewed by security. This one is made by recruiters and hiring managers against a threat model that assumed the person on the video call was the person on the resume.

Does this test our recruiters as individuals?

No. Reporting is organizational and never individual. There are no named interviewers, no team leaderboards, and no per-person scores in any deliverable. The finding is about which verification step exists, which one is skipped under scheduling pressure, and which one has no owner at all.

Do you use a real person's face or voice?

The default candidate is a fully synthetic persona built from generated media, so no real individual is impersonated. Where a scenario calls for impersonating a named executive or a named employee, for example a cloned hiring manager calling a recruiter, we require documented written consent from that individual before any asset is generated, and the scope names them explicitly.

Do you apply to a real open role?

Only with authorization and a named approver inside talent acquisition. Most engagements run against a controlled requisition or a shadow pipeline so that no genuine applicant is displaced and no live offer is ever issued. Requisition selection, submission volume, and the abort point are agreed and signed before anything is submitted.

How far do you take the scenario?

To the agreed stop line and no further. Typical engagements run to the point of offer acceptance or provisioning request, which is where the interesting failures sit, and stop before an account is created or hardware is dispatched. Some clients extend scope to include equipment dispatch to a controlled address, because that is the step that exposes address and delivery verification.

Will this disrupt recruiting operations?

No. The engagement runs externally with no software installed and no integration into your ATS or HRIS. Submission volumes and interview scheduling windows are agreed so that recruiter workload and time to hire stay within normal range.

What do we receive at the end?

A per-stage findings report covering which verification step stopped the candidate and which did not, the point at which the process could have caught it and did not, an OSES™ Score with the sector position alongside it, prioritized remediation aimed at the specific procedure that broke, and evidence written for auditors and insurers without a rewrite.

Find out how far a synthetic candidate would get

Thirty minutes. We will walk your pipeline stage by stage and identify which verification step is worth submitting against first.

No ATS integration Runs fully external Organization-level reporting

Or read the full assessment methodology.