Identity · 5h ago
HYPR published a survey-backed snapshot on September 15 showing that fraudulent candidates often get corporate credentials before anyone catches them. In the study, 42% of fake hires made it through pre-hire screening and 3% were identified the same day they were officially hired, leaving an average 5.73 days of unmonitored access.
The mechanism is simple: a bogus applicant can pass interviews and checks well enough to receive normal IT login credentials, then use them like any employee while the identity gap remains hidden. HYPR says the problem is not one failed control but a broken handoff, with HR, talent acquisition, IT, and security operating as disconnected checks.
For organizations that issue accounts, MFA, or device access before identity assurance is complete, the exposure begins at onboarding, not after a breach. The lasting risk is an insider with valid access on paper and a several-day window to reach data before traditional monitoring or post-hire review catches up.
1 source covering this story
Most Fraudulent Hires Receive Credentials Before Detection
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations
Part of the PlainSec briefing for 2026-09-15