Breaking
Cyber CrimeDeveloping Story

Fake Hires Get Network Access First

A HYPR report finds most fraudulent hires receive corporate credentials before detection, leaving firms exposed to insider risk.

··1 hour ago·6 min read
Two professionals shaking hands across a table
Photo by Vitaly Gariev on Unsplash

Fraudulent candidates are slipping past pre-hire screening and into corporate roles at scale, and by the time anyone notices, they often already hold the keys to the network. According to a new report by HYPR, most fraudulent hires receive corporate credentials and internal network access before they are detected — an average window of nearly six days of unmonitored access.

The findings, published September 15, arrive during National Insider Threat Awareness Month 2026, as US officials press organizations to treat hiring fraud as a genuine insider-risk problem rather than a background-check formality.

Credentials Arrive Before Suspicion

HYPR's data paints a hiring pipeline that is porous at every stage. Fraudulent candidates successfully navigate pre-hire screening and take up their roles in 42% of cases, according to the report. Onboarding, rather than stopping them, effectively hands them access.

Detection, when it comes, is rarely swift. Just 3% of fraudulent hires are spotted on the same day they are officially hired. Around a third — 32% — are discovered within one to three days, 45% within four to six days, and 20% go undetected for up to three weeks.

The cumulative effect: fraudulent hires enjoy an average of 5.73 days of unmonitored access to corporate networks. That is five-plus days of email, file shares, internal applications and whatever privileged systems their new role touches, all before anyone flags them.

Bojan Simic, CEO and co-founder of HYPR, put the shift bluntly in the study.

“Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT.”

— Bojan Simic, CEO and co-founder of HYPR

How Fraudsters Are Caught

When organizations do catch fraudulent candidates during the hiring process, the mechanisms are telling. Human instinct accounts for 68% of detections — an interviewer or recruiter sensing something off, rather than a control firing cleanly.

The most common pre-hire detection points are screening, at 52%, and interviews, at 45%. Technical assessments follow at 41%, with onboarding at 42%. In other words, detection is spread across a handful of stages, none of which reliably stops fraud on its own.

HYPR described that arrangement sharply in the study dated September 15.

“A process that catches fraud at every different stage isn’t really a security funnel – it’s a set of disconnected checks operating in silos. Because no single stage reliably stops candidate fraud, clearing an earlier stage offers no guarantee of identity assurance.”

The implication is a chain of hand-offs — recruiter to interviewer to assessor to IT — in which each party may assume an earlier stage already vetted the person in front of them.

Who Owns Hiring Identity Risk

The report also flagged a split in accountability across the organizations surveyed. About half of HR executives — 53% — said they take ownership of hiring identity risk before an offer is accepted. The talent acquisition team was named by 19%, compliance and legal by 10%, security by 10%, and IT by 7%.

HYPR said this suggests many organizations operate on the assumption that IT and security only pick up candidate identity risk after the hire is complete — an assumption that leaves the pre-hire window, precisely when credentials are being provisioned, thinly governed.

The scale of the problem is not marginal. Nearly all — 98% of 500 US HR executives surveyed — said they had encountered candidate fraud first hand. And 89% reported heightened concern about hiring fraud over the past two years. This is not a fringe event for most HR teams; it is a recurring one.

The Remote Interview As Attack Path

The threat model HYPR describes has been gaining public attention. During National Insider Threat Awareness Month 2026, on September 9, the US Cybersecurity and Infrastructure Security Agency released an update to its Insider Threat Mitigation Guide, highlighting how malicious actors are using AI tools to apply for and obtain remote IT jobs and thereby gain privileged access to enterprises.

That tactic has been used extensively by North Korean actors seeking employment in Western firms in recent years, for purposes including data theft and subsequent extortion. Remote interviewing and onboarding, in this model, become a direct route to authenticated, privileged access — no exploitation required.

Facing that reality, the report found that around 60% of identity verification and multi-factor authentication budgets are only authorized reactively, following a security breach. Spending, in many cases, follows the incident rather than preceding it.

Why The Access Window Matters

The 5.73-day average access window is the detail worth sitting with. A new hire with legitimate credentials is not an intruder that endpoint detection flags — they look like an employee, because, for the purposes of the system, they are one. Access is granted through normal onboarding, not through a compromised account or a zero-day.

That means the usual signals — anomalous logins, brute-force attempts, malware alerts — may not fire at all. The fraud is an identity problem at the front of the pipeline, not an intrusion at the back. The data theft or espionage, if it happens, occurs with authorized keys to authorized systems.

Combine that with the detection distribution in HYPR's study, and the practical picture is one of delay: detection tends to happen days after the fact, and often through human judgment rather than a deterministic control. A faster, identity-centric check at the pre-hire and onboarding stage would compress the window, but the findings suggest few organizations currently have one that operates end to end.

An Identity Problem, Not A Screening Formality

For security and HR leaders, the HYPR findings point to a specific gap: the period between a candidate accepting an offer and the moment their credentials are issued. In many organizations, that window is owned by HR or talent acquisition, while IT and security, per the report, are largely assumed to step in only post-hire.

The data on detection points reinforces why siloed checks fail. Screening catches 52%, interviews 45%, technical assessments 41%, onboarding 42% — none dominant, none a backstop. Fraud that clears one gate is not meaningfully more likely to be stopped at the next.

There is also the budget signal: the report's finding that about 60% of identity verification and MFA budgets are approved only reactively, after a breach, suggests that pre-hire identity assurance is frequently funded out of crisis rather than design.

What It Could Mean For Firms

The immediate consequence for employers is that hiring fraud should be treated as an insider-risk control, not a recruiting nuisance. If most fraudulent hires receive credentials and network access before detection, then the exposure is not hypothetical data risk — it is a live authenticated foothold of nearly six days on average.

For security teams, this suggests re-examining where identity verification sits in the hiring lifecycle, and whether IT and security have any role before credentials are minted. For HR leaders, it points to the value of consistent, identity-focused checks at the points HYPR measured — screening, interview, assessment and onboarding — rather than relying on any single gate.

The broader inference is that as AI-assisted applications make it cheaper to pass remote interviews, the burden shifts toward verifying who a candidate actually is at the moment access is granted, not after. Firms that wait for a breach to fund that capability, the HYPR data suggests, may be funding it five-plus days too late.

  • 42% of fraudulent candidates navigate pre-hire screening and take up their roles.
  • 3% are detected on the same day they are officially hired.
  • 32% are found within one to three days; 45% within four to six days; 20% within three weeks.
  • Fraudulent hires have an average of 5.73 days of unmonitored access.
  • 68% of detected fraudulent candidates are identified by human instinct.
  • 98% of 500 US HR executives surveyed had experienced candidate fraud first hand; 89% expressed heightened concern over the past two years.
  • About 60% of identity verification and MFA budgets are authorized only after a breach.
#hiring fraud#insider threat#identity verification#hr security#candidate fraud#credential access

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories