Blog Main Image
September 22, 2026

Hiring fraud: when attackers are issued real credentials

Most security advice assumes the attacker is outside the organisation, trying to talk their way in. One category of attack skips that problem altogether. The candidate applies for an advertised role, interviews well, accepts the offer, and is then handed a laptop, a company email address and a working set of credentials by the IT team. There is no malicious attachment and no stolen password. The access was granted through the front door, by people following the process exactly as written.

A report published on 15 September 2026 by the identity firm HYPR puts some numbers against how often that happens. In a survey of 500 US HR executives, 98% said they had dealt with candidate fraud first hand, and 89% said their concern about it had grown over the previous two years. The report found that in 42% of cases a fraudulent candidate cleared pre-hire screening and went on to start the job.

The gap between the start date and the discovery

Clearing screening is only half of the story. The figure that matters for a security team is how long a fraudulent hire keeps working before anyone realises. According to the HYPR research, only 3% were identified on the day they were formally hired. Another 32% were found within one to three days and 45% within four to six days. The remaining 20% went undetected for as long as three weeks. Averaged across the responses, a fraudulent hire has roughly 5.73 days of access to corporate systems before anyone catches on.

Five or six days is a long time for an account that carries a verified identity in the directory. In that window the person can read shared drives, sit in team meetings, pull down internal documentation and, depending on the role, reach source code or customer records. From a monitoring point of view none of it looks like an intrusion. It looks like a new starter finding their feet.

What the fraud is usually for

The best documented version of this pattern is the North Korean remote IT worker scheme. In April 2026 the US Department of Justice announced prison sentences for two US nationals who had helped North Korean IT workers pose as US residents to win remote jobs. Court documents describe a scheme running from around 2021 until October 2024 that used the stolen identities of more than 80 US persons to obtain work at more than 100 US companies, including many in the Fortune 500. It generated more than $5 million for the North Korean government, and victim companies were left with at least $3 million in legal fees, remediation and other costs.

The mechanics are worth reading because they are so ordinary. The US-based facilitators ran what investigators call laptop farms: corporate laptops shipped to residential addresses, then wired up to keyboard-video-mouse switches so that workers overseas could operate them as if they were sitting in New Jersey. Shell companies with plausible names were registered so the workers appeared to be attached to real US businesses. In one instance the access was used to reach technical data controlled under US arms export regulations, held by a California defence contractor. The FBI's advice in that announcement was blunt: organisations should strengthen their remote hiring processes.

The motive is not always espionage. The FBI has published public service announcements warning that workers hired this way have exfiltrated proprietary data and then attempted to extort their employers. Ordinary fraud accounts for much of the rest.

Why the hiring pipeline keeps missing it

The survey figures on detection are the most revealing part of the report. Among fraudulent candidates who were spotted before being hired, 68% were identified by human instinct rather than by a process or a tool. Screening accounted for 52% of pre-hire detections, interviews 45%, onboarding 42% and technical assessments 41%.

At first glance that spread looks like healthy defence in depth. Read it again and the weakness appears. No single stage catches most of the fraud, which means passing one stage tells you very little about whether the identity behind the application is real. The report describes the result as a set of disconnected checks operating in silos rather than a funnel that genuinely narrows risk.

Fishbone diagram showing how screening, technical assessment, interviews and onboarding each catch only part of candidate fraud, leading to valid credentials being issued to a fraudulent hire
Each stage of hiring catches some candidate fraud, but none of them catches most of it. Clearing one stage says nothing about identity.

Ownership is fragmented in the same way. 53% of the HR executives surveyed said their own function owned identity risk before an offer was accepted, with the remainder split between talent acquisition, compliance and legal, security and IT. Around 60% said identity verification and multi-factor authentication budgets were only signed off reactively, after a security incident had already happened.

Regulators and agencies have noticed

On 9 September 2026, during National Insider Threat Awareness Month, CISA published an updated version of its Insider Threat Mitigation Guide, first released in 2020. The revision adds material on artificial intelligence, hybrid and remote working, access control, visitor screening and involuntary separations.

The AI section covers the problem from both directions. Insiders with privileged access could poison training data or push sensitive information into unapproved AI services. External attackers can use AI-generated messages and deepfakes to deceive staff, which is exactly the capability that makes a convincing remote interview cheap to stage. The remote working section asks organisations to revisit how equipment, documents and home network connections are handled away from a main office.

What organisations can do about it

  • Make identity verification a control, not a courtesy. Checking a document image emailed by the candidate is not the same as verifying that the person on the call is the person on the document. Decide which stage of hiring owns that check and write it down.
  • Treat the interview as an identity checkpoint. A camera that never works, an audio-only final round, or a candidate whose appearance or accent shifts between calls are all worth a second look. Give interviewers permission to pause the process rather than push on politely.
  • Separate the person from the device. A laptop posted to an address that does not match the employment record, or a new starter who only ever connects through a commercial VPN or remote access tool, is a question worth asking on day one rather than day six.
  • Stage the access. Very few roles need full standing access on the first morning. Widening permissions over the first fortnight, after identity has been confirmed in person or through a verified check, shrinks that 5.73 day window considerably.
  • Close the handover between HR and security. Recruiters and hiring managers are usually the first to feel that something is off, and the survey suggests they are the ones catching it. They need a fast, blame-free route to raise a concern with security, and an expectation that it will be acted on.
  • Extend verification beyond the start date. Identity checks at the service desk, on password and MFA resets, and on requests to change payroll or device details matter just as much. A fraudulent hire who can talk the help desk into re-enrolling MFA on a new device has undone the work of the hiring process.

The bottom line

Candidate fraud is uncomfortable because it turns a helpful process into an attack path. Recruiters and hiring managers are not failing when a fraudulent applicant gets through. They are being asked to make an identity decision using tools designed to assess skills and fit, which is a process problem and a fixable one.

The people in the hiring chain are also the best detection capability most organisations have, given that 68% of pre-hire catches came from human instinct. The work is to give that instinct somewhere to go, back it with verification that actually proves identity, and stop treating a successful interview as evidence of who someone is.

Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.

Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Scroll To Top Arrow