BBC warns AI-generated faces are becoming a new risk in online job scams

BBC warns AI-generated faces are becoming a new risk in online job scams

N
News Editor
2026-07-28 02:15:55
The BBC has published an interactive test asking readers to tell real human faces from AI-generated ones, and its main takeaway is not that synthetic faces are flawless, but that people tend to overestimate their ability to spot them. That gap is turning deepfakes into a practical tool for social-engineering attacks tied to online hiring. The report says fake recruitment outreach has become an effective lure, especially for people working in tech, Web3, and AI. Attackers often pose as recruiters, well-known companies, or startup hiring teams on LinkedIn, X, and Telegram, offering attractive remote roles and salaries. Once a target agrees to interview, they may be asked to download an “interview app,” install a meeting tool, open a macro-enabled file, or run a coding test that actually contains malware or an infostealer. The BBC also cites research from the Australian National University showing that participants identified AI faces with an accuracy rate of about 41%. According to the report, today’s most convincing AI faces often look suspicious not because they appear broken, but because they seem too symmetrical, too polished, and too statistically perfect.
AI deepfakeBBConline job scamsWeb3 securityinfostealercrypto wallet securityremote hiring

As remote work and global hiring become standard practice, online interviews are now routine across tech companies and startups. At the same time, fast progress in generative AI is making it harder to distinguish real people from synthetic images.

The BBC recently launched an interactive quiz that asks readers to tell apart real human faces and AI-generated ones. It said that even people who are relatively strong at facial recognition perform only slightly better than others, while most people are overly confident in their own judgment.

The BBC’s warning: the bigger problem is misplaced confidence

According to the BBC, the key warning is not that AI has become perfect. The larger issue is that people widely overrate their ability to identify AI-generated faces. That creates room for deepfakes to be used in investment scams, fake identities, and fraudulent online interviews as part of broader social-engineering attacks.

Fake hiring pitches are becoming a favored social-engineering route

Traditional scam emails often trigger suspicion. Job offers delivered through hiring platforms or social networks can be much more effective because they lower a target’s guard.

The report says attackers impersonate well-known companies, Web3 startups, AI firms, or headhunters, then reach out to engineers, designers, and product managers on LinkedIn, X, or Telegram with seemingly generous pay packages and remote job opportunities.

Once a candidate agrees to an interview, the attack can begin. Victims may be told to:

  • download an “interview software” package
  • install a designated video tool
  • open a document that requires macros to be enabled
  • run a testing program or coding challenge

Those files may contain trojans or infostealers. If executed, they can steal passwords, cookies, corporate VPN credentials, SSH keys, and even private keys tied to crypto wallets.

The BBC report says these attacks have increasingly targeted the Web3 and AI sectors. Workers in those fields often hold crypto wallets and control access to multiple community or social accounts. If an attacker compromises one engineer, that breach may open the door to a company’s internal systems and, in some cases, supply-chain attacks.

Victim accounts have surfaced on X

The article says a number of related cases have appeared on X in recent years.

Case 1: a fake interview platform installs malware

Some engineers said they received what looked like recruiting messages from well-known Web3 projects. They were told to download a dedicated interview app first. Nothing looked wrong immediately after installation, but within hours their Gmail accounts were accessed, GitHub tokens leaked, MetaMask wallets were drained, and Telegram accounts were taken over, all with little obvious warning during the attack.

Case 2: a coding test that is actually malicious software

Another common setup uses a technical assessment as cover. Applicants are asked to download a compressed file that includes not only the test prompt but also a program they must run. Once launched, it can silently install an infostealer and send data back to the attacker’s server. The report says this method has appeared repeatedly in the cryptocurrency sector in recent years.

Case 3: fake Zoom or Google Meet updates

Other attacks happen just before a scheduled interview. Applicants are told that their Zoom version is outdated and needs an update, or that they must install the company’s meeting tool. The download link may look legitimate and may even use a domain name closely resembling an official one, but the software being installed is malicious.

North Korean fake IT worker cases add to concerns around remote hiring

Beyond fake recruiting campaigns, the report points to another issue that has drawn heavy attention in recent years: North Korean operatives posing as IT workers to secure jobs at overseas companies.

According to the article, some North Korean personnel have used false identities, fake resumes, and remote-work openings to obtain engineering jobs at foreign firms, then route salaries back to the North Korean government. The activity has expanded from the United States into European markets in recent years.

What AI faces now look like: less “wrong,” more “too perfect”

People once relied on obvious visual errors such as extra fingers or distorted backgrounds to detect AI-generated images. The BBC says newer models have corrected most of those flaws.

Citing research, the report says the most advanced AI faces now often stand out not because something looks strange, but because everything looks too average, too symmetrical, and too perfect. Researchers said AI tends to generate facial features that align with broad statistical patterns, which can produce several recurring traits:

  • unusually symmetrical left and right sides of the face
  • overly standard facial proportions
  • almost no skin imperfections
  • lighting that looks too even for real photography
  • natural-looking expressions with limited subtle emotional variation

In other words, today’s AI faces may not look less human. They can look more perfect than real people.

The BBC also cites research from the Australian National University, or ANU, saying participants identified AI-generated faces with an accuracy rate of only about 41%, which was even worse than random guessing.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.