IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Fraudulent hires get credentials before detection, HYPR

Fraudulent hires get credentials before detection, HYPR

Fri, 2nd Oct 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

HYPR's research found that 98% of fraudulent hires receive corporate credentials before they are detected. It also found that 68% of cases are uncovered through human observation or instinct rather than technology.

The findings point to a gap between recruitment and security operations, as responsibility for identity risk shifts from HR to IT when a candidate becomes an employee. Before a worker starts, 53% of HR leaders say they own identity risk, compared with 17% of IT and security teams. That balance reverses after credentials are issued.

The research combined a survey of 500 US HR leaders in talent acquisition, HR operations and HR technology with a separate study of 950 IT security decision-makers across the US, EMEA and APAC, produced with S&P Global / 451 Research.

According to the data, 42% of organisations detect hiring fraud only after the first day of employment. Discovery typically takes four to six days, by which point fake hires have usually been given active credentials and access to internal systems.

The report places the problem within a broader pattern of identity-based attacks slipping past automated controls. Across enterprise identity attacks more widely, security tools catch 53% of threats, while the remaining 47% are discovered through coworker reports, internal audits or external notifications.

Ownership gap

The transfer of responsibility between departments is a central theme in the research. HR leaders were more likely to claim ownership of identity risk before day one, while security and identity access management teams were more likely to take responsibility once credentials had been created.

That handover creates what HYPR described as an unmonitored stretch in the employee lifecycle. Synthetic candidates can move through interviews and onboarding checks before entering corporate systems with legitimate access.

Leaders closest to identity infrastructure also expressed relatively low confidence in existing controls. HR technology directors reported below-average confidence in catching fraud, at 41% versus 53% across all HR leaders surveyed, while IT teams often still rely on coworkers to spot suspicious hires.

The operational burden can continue long after a fraudulent worker is identified. Resolving a single fake-hire incident takes at least one to three weeks in many organisations, while nearly a quarter of respondents said full resolution can take one to three months.

Growing concern

Concern about hiring fraud has risen sharply among HR leaders. Even so, spending on identity verification and multi-factor authentication often follows a breach rather than preceding one, with about 60% of those budgets authorised only after an incident.

HYPR linked the trend to changes in how impostors present themselves during recruitment. Generative AI, voice cloning and synthetic identities are helping fraudulent applicants bypass traditional screening and remote interview processes.

The company said it encountered the issue itself when it stopped a fraudulent remote IT worker during identity verification after the candidate had passed multiple live video interviews. The individual was intercepted before any credentials were issued.

According to HYPR, that case reflected tactics associated with the wider fake IT-worker threat, including operations linked to North Korea. Businesses and governments have increased scrutiny of remote hiring channels as concerns grow over impostors seeking payroll access, sensitive data and entry to internal networks.

Bojan Simic, Chief Executive Officer and Co-Founder of HYPR, set out the company's view of the risk in a statement accompanying the findings. "Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT," Simic said.

He added: "Human intuition is not a security control. Sceptics might point to low reported numbers, but the lack of purpose-built verification technology means the industry is simply blind to the problem; there are vastly more fraudulent workers embedded in organizations than current data reflects."