Most Fraudulent Hires Receive Credentials Before Detection
Most Fraudulent Hires Receive Credentials Before Detection
According to a new report by HYPR, most fraudulent hires receive corporate credentials and internal network access before being detected. 🚨 Fraudulent candidates successfully navigate pre-hire screening and take up their roles in 42% of cases. Just 3% are detected as fraudulent on the same day they are officially hired.
Key Findings:
- 32% are discovered within one to three days.
- 45% within four to six days.
- 20% go undetected for up to three weeks.
This means that fraudulent hires have an average of 5.73 days of unmonitored access to corporate networks, posing significant data security risks to organizations. Almost all (98%) of 500 US HR executives surveyed said they had experienced candidate fraud firsthand, while 89% expressed heightened concern over hiring fraud in the past two years.
Bojan Simic, CEO and co-founder of HYPR, warned: “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT.” Among the fraudulent candidates detected during the hiring process, 68% are identified by human instinct. Screening (52%) and interviews (45%) are the most common pre-hire detection points, followed by technical assessments (41%) and onboarding (42%).
The report also highlighted a significant discrepancy in responsibility for identifying candidate fraud pre-hire. About 53% of HR executives surveyed took ownership for hiring identity risk before an offer is accepted, while 19% said the talent acquisition team is responsible, 10% for compliance/legal, 10% for security, and 7% for IT.
The report findings, published on September 15, come amid National Insider Threat Awareness Month 2026. On September 9, the US Cybersecurity and Infrastructure Security Agency (CISA) released an update to its Insider Threat Mitigation Guide, highlighting how malicious actors are using various AI tools to assist them in applying for and obtaining remote IT jobs to gain privileged access into enterprises. This tactic has been extensively used by North Korean actors to gain employment in Western firms for purposes such as data theft and even subsequent extortion.
Despite these publicized threats, the HYPR report found that around 60% of identity verification and multi-factor authentication budgets are only authorized reactively following a security breach.