Join our Newsletter — 33% off our NHI Course
Home Glossary Identity Beyond IAM Interview Injection Attack
Identity Beyond IAM

Interview Injection Attack

← Back to Glossary
By NHI Mgmt Group Updated August 24, 2026 Domain: Identity Beyond IAM

An interview injection attack is a tactic that substitutes or manipulates the video stream during a remote interview so the interviewer sees a controlled presentation instead of the actual candidate. It can involve virtual cameras, pre-rendered footage, or stream substitution. The control objective is to prove capture integrity, not just video delivery.

Expanded Definition

An interview injection attack is a form of session or capture manipulation in which the displayed video in a remote interview is not the authentic live feed from the candidate. Instead, an attacker may substitute a virtual camera, replayed footage, or a routed feed that presents a controlled persona. The security issue is not simple spoofing of identity; it is the loss of capture integrity at the point where the interviewer assumes the stream is live and unaltered.

In practice, this concept sits at the intersection of identity verification, remote proctoring, and NHI risk because an attacker may also coordinate scripts, tooling, or AI agents to sustain deception over time. Guidance is still evolving across vendors and platforms, so organisations should treat the term as a capture-integrity problem rather than only a video-quality issue. For adjacent control thinking, NIST SP 800-53 Rev 5 Security and Privacy Controls provides useful control families for auditability, monitoring, and system integrity.

The most common misapplication is treating it as ordinary account impersonation, which occurs when teams check the interview login but never verify whether the camera source itself has been substituted.

Examples and Use Cases

Implementing detection and prevention rigorously often introduces friction in the candidate experience, requiring organisations to weigh smoother interviews against stronger verification of stream authenticity.

  • A recruiter conducts a video interview while the candidate uses a virtual camera tool to replay a pre-recorded, polished response set, masking the real person behind the screen.
  • An attacker intercepts the conferencing workflow and presents a substituted feed while keeping audio, chat, and timing aligned enough to avoid immediate suspicion.
  • A fraudulent applicant uses a remote support or relay setup so a different person appears on camera while the nominal candidate controls the keyboard off-screen.
  • An AI-assisted deception workflow combines face-replacement, scripted prompts, and live stream control to maintain consistency across a long interview or assessment session, echoing broader patterns seen in Anthropic — first AI-orchestrated cyber espionage campaign report.
  • Security teams validate whether a candidate-facing platform logs device, camera, and media-source signals, then compare that telemetry with known abuse patterns from CISA cyber threat advisories.

For teams mapping deception paths, the MITRE ATT&CK Enterprise Matrix can help describe the broader intrusion workflow, while the MITRE ATLAS adversarial AI threat matrix is relevant when the attack uses generative tools to support impersonation.

Why It Matters for Security Teams

Interview injection attacks matter because they undermine trust in remote hiring, contractor onboarding, and high-assurance screening flows. If the interview channel can be manipulated, then any downstream decision based on visual presence, responsiveness, or facial confirmation may be built on false evidence. That creates risk not only for hiring integrity, but also for privileged access decisions when a candidate later receives credentials, repository access, or NHI-related entitlements.

Security teams should treat this as a verification design problem: what proves that the stream is live, local, and bound to the claimed subject? Controls can include device attestation, liveness checks, verified session telemetry, stronger step-up verification, and review of media-source integrity signals. The governance lesson aligns with the control intent behind NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where monitoring and integrity evidence are required.

Organisations typically encounter the operational impact only after a false hire, suspicious access grant, or incident review exposes that the interview itself was never the authentic source of trust, at which point interview injection attack controls become operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63IALDigital identity assurance applies when interview identity must be bound to the real person.
NIST CSF 2.0PR.AAIdentity and authentication outcomes align with verifying session authenticity and trust.
NIST SP 800-53 Rev 5SI-4Monitoring and anomaly detection support identifying manipulated media or session behavior.
OWASP Non-Human Identity Top 10NHI-08Attackers may abuse automated or non-human components to sustain interview deception.
NIST AI RMFGOVERNAI-assisted deception makes governance and accountability relevant to this attack class.

Instrument interview platforms to detect media-source anomalies and suspicious session patterns.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org