Opens in a new tab
vmblog logo 2024 wht (updated)

HYPR Research: Fraudulent Workers Are Getting Corporate Credentials Before Companies Know They’re Fake

Share: 

David Marshall | Published: September 15, 2026

New research from HYPR found that 98% of HR executives have encountered candidate fraud. More concerning, when a fraudulent candidate is actually hired, 98% receive active corporate credentials before they are detected.

The findings highlight a growing security gap as attackers use generative AI, synthetic identities, voice cloning and other techniques to make fraudulent candidates increasingly difficult to spot during remote hiring.

According to HYPR’s research, 42% of organizations do not identify a fraudulent hire until after their first day of employment. Detection then takes an average of four to six days, potentially giving an impostor nearly a week of access to corporate systems.

Despite growing investment in security technology, humans remain surprisingly important to catching them. Sixty-eight percent of fraudulent hires are discovered through human observation or “gut feeling” rather than automated controls.

“Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO and co-founder of HYPR. “Human intuition is not a security control.”

The problem extends beyond recruiting. HYPR found that automated security tools identify only 53% of identity-based attacks overall. The remainder are uncovered through coworker reports, internal audits or external notifications.

One reason fake workers can slip through is a disconnect between the teams responsible for hiring employees and those responsible for securing their identities.

Before an employee’s first day, 53% of HR leaders say they own identity risk, compared with just 17% of IT and security teams. Once corporate credentials are provisioned, that relationship reverses: security and identity teams claim 55% of responsibility, while HR falls to 15%.

That handoff creates a potentially dangerous gap between verifying that a candidate is who they claim to be and granting that person access to corporate systems.

The consequences can also continue long after the impostor is discovered. HYPR found that resolving an incident typically takes at least one to three weeks, while 24% of organizations require between one and three months to fully remediate a fraudulent hire.

The research suggests organizations are increasingly aware of the threat but remain largely reactive. Nearly 90% of HR leaders report heightened concern about hiring fraud, yet approximately 60% of identity verification and multi-factor authentication budgets are authorized following a security incident rather than beforehand.

Technical teams are also among the least confident in existing defenses. HR technology directors report 41% confidence in their ability to detect hiring fraud, below the 53% average among HR leaders, and take an average of eight days to uncover an impostor. Meanwhile, 51% of IT teams say they rely on reports from coworkers to identify fraudulent hires.

The results point to an increasingly important challenge for enterprises: identity security can no longer begin when an employee receives a username and password. As attackers increasingly target the hiring process itself, organizations need to establish whether someone is legitimate before that identity becomes trusted inside the enterprise.