Deepfake Job Interviews and Vishing Hit Enterprises

ZDNet Security · High sophistication
Last updated August 3, 2026

CrowdStrike warns that attackers are using AI to make social engineering faster and more convincing, including AI-generated resumes and deepfake job interviews to infiltrate companies. The report also describes vishing campaigns that quickly pivot from stealing accounts to stealing data from SaaS apps, sometimes in under five minutes.

Key findings

  • A DPRK-linked group (Famous Chollima) is using AI-generated resumes and deepfake interviews to gain entry to crypto/blockchain companies.
  • Cordial Spider and Snarky Spider use phone-based social engineering (vishing) to compromise single sign-on accounts and steal data from SaaS apps.
  • CrowdStrike reports that AI-driven activity creates more “signals” that make it harder to separate normal AI use from malicious behavior.

Who’s being targeted

  • Commonly targeted roles: Human Resources / Recruiting, Hiring managers, All employees, IT helpdesk, Identity and Access Management (IAM) teams, SaaS administrators.
  • Affected industries: Cryptocurrency and blockchain, Technology/SaaS, Any enterprise using SSO and AI/LLM services.
  • Attack channels: linkedin, email, website, vishing.
  • Impersonated: Job candidate / applicant, IT helpdesk / identity support (SSO support).

Awareness takeaways

  • Treat job recruitment workflows as a security surface: verify applicant identity and be cautious of deepfake-enabled interviews.
  • Train staff to resist phone-based account takeovers: never share one-time codes or approve unexpected login prompts during unsolicited calls.
  • Assume attacks can move from login takeover to data theft extremely quickly; escalate suspicious access issues immediately.

Red flags to watch for

  • Resume and experience seem unusually polished or inconsistent under questioning
  • Video/audio quality or timing looks unnatural (possible deepfake)
  • Pressure to move quickly through screening or avoid standard verification steps
  • Unsolicited call claiming urgent account issues
  • Requests to approve a login/push or share one-time codes
  • Caller pushes to bypass normal ticketing/verification steps
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a perfect resume, a flawless video interview… and the “candidate” isn’t even real. CrowdStrike reports groups like Famous Chollima using AI resumes and deepfake interviews to slip into crypto and blockchain companies, while Cordial Spider and Snarky Spider use vishing to hijack single sign-on and raid SaaS data in under five minutes. Here’s the twist: the fake candidate pressures you to skip normal checks, and the “IT support” caller says, “We’re seeing an access issue, can you read me that one-time code or approve that push so we can fix it?” That’s the handoff from deepfake to instant data theft. If anyone on a call asks you to share a one-time code or approve an unexpected login, whether it’s a candidate or “IT support”, hang up and report it to security immediately.

Similar attacks

Malicious GitHub Issue Can Hijack AI Coding Agents

Malicious GitHub Issue Can Hijack AI Coding Agents

Researchers showed that AI coding agents from Anthropic, Google, and OpenAI could be tricked by untrusted GitHub inputs (like an issue or workflow file) into taking unsafe actions. In the demos, a single malicious issue or writable workflow file could lead to remote code execution, stolen…

August 6, 2026
GitHub Issue Trick Turns AI Coders Against Repos

GitHub Issue Trick Turns AI Coders Against Repos

Researchers showed that a single public GitHub issue (from someone with no repo access) could steer popular AI coding agents into running dangerous commands, exposing tokens, and changing repositories. The risk comes from AI agents reading untrusted issue/PR text while also having access to…

August 6, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
AI Chatbots Outperform Humans in Romance Scams

AI Chatbots Outperform Humans in Romance Scams

Researchers simulated “pig butchering” romance-style scams and found an AI chatbot built trust more effectively than a human scammer over a week of texting. In the test, victims were significantly more likely to comply with the AI’s request to install an app, showing how AI could automate the long…

July 30, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026