A new report from HYPR indicates that 98% of fraudulent hires obtain company credentials before their deception is detected. This finding highlights a significant vulnerability in enterprise identity security, particularly a "blind spot" during the 90-day period between hiring and onboarding.
The report suggests that adversaries are increasingly bypassing traditional network breaches by successfully navigating remote interviews and receiving legitimate credentials directly from IT departments. This method allows fraudulent individuals to gain internal network access before their true identities are discovered.
While 98% of HR leaders surveyed reported direct experience with candidate fraud, 96% expressed confidence in their organization's ability to detect it. This discrepancy points to a potential overestimation of current defense capabilities. Detection often occurs through fragmented checkpoints such as screenings, interviews, onboarding, active employment, and technical assessments, averaging 2.2 detection points per incident. This fragmented approach suggests a lack of a consistent, primary barrier against fraud.
Identity verification tools are frequently limited to specific events like account creation, sensitive transactions, or account recovery. Outside these defined checks, fraudulent hires can remain undetected, leaving organizations reliant on manual processes and employee vigilance to identify suspicious behavior. Although recruitment platforms and applicant tracking systems are beginning to integrate identity verification and anti-fraud features, particularly targeting AI-generated candidates and synthetic agents during application and screening stages, third-party security tools only detect 53% of identity-based and AI-driven attacks. The remaining cases are discovered manually through employee reports, internal audits, or external alerts.
A notable "confidence gap" was observed among leaders responsible for identity and hiring technology, who generally expressed less assurance in their organizations' fraud detection capabilities. The IT and telecommunications sector, despite being the most technically equipped, reported a higher reliance on manual observation than any other group. Education showed the largest disparity between concern about hiring fraud and confidence in existing defenses. Conversely, manufacturing and utilities reported high levels of both concern and confidence, which HYPR attributes to their prevalence of in-person hiring and face-to-face identity checks. Sales, media, and marketing was the only sector where confidence exceeded concern, heavily depending on employees to identify and report suspected fraud.
The report also identifies an "identity risk handoff" problem. While HR typically manages recruitment and IT/security takes over once a new hire receives access, the period between these stages often lacks a clearly defined owner. Attackers exploit this transition to infiltrate organizations while responsibility is shifting between teams. This exposure can persist even after hiring, especially if fraud is only discovered after credentials have been issued.
Resolving a hiring fraud incident typically takes one to three weeks, incurring financial and operational costs through delayed hiring, backfilling, lost productivity, security exposure, compliance risks, and team disruption. In response to such incidents, companies have implemented an average of 2.52 actions, including identity verification technologies. However, investment in identity security tends to be reactive, with approximately 60% of identity verification and multi-factor authentication (MFA) spending being triggered by a security breach rather than proactive measures.






