“Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” Bojan Simic, CEO and co‑founder of HYPR, warned in a study published September 15.
Detection timelines and the unmonitored access window
HYPR’s report finds that fraudulent candidates commonly clear pre‑hire screening and take up roles: 42% of fraudulent hires successfully start work. Detection rarely happens immediately. Just 3% of these hires are identified as fraudulent on the same day they are officially hired; 32% are discovered within one to three days; 45% within four to six days; and 20% remain undetected for up to three weeks. Taken together, those figures produce an average of 5.73 days of unmonitored access to corporate networks — a period HYPR describes as posing significant data security risks to organizations.
How fraudulent candidates are caught — and how they’re missed
When fraud is identified during the hiring process, the most common detector is human instinct: 68% of pre‑hire detections are attributed to people’s instincts. HYPR’s survey of detection points shows screening (52%) and interviews (45%) lead the list of pre‑hire discovery mechanisms, followed by onboarding (42%) and technical assessments (41%). The study frames these points as “a set of disconnected checks operating in silos,” arguing that no single stage reliably stops candidate fraud and that clearing one stage “offers no guarantee of identity assurance.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOwnership gaps: who is responsible for pre‑hire identity risk?
The HYPR survey of 500 US HR executives documents a wide divergence in who takes responsibility for spotting candidate fraud before an offer is accepted. About half (53%) of HR executives said they take ownership for hiring identity risk pre‑offer; 19% pointed to the talent acquisition team; 10% cited compliance/legal; 10% assigned responsibility to security; and 7% to IT. HYPR characterizes these allocations as indicating an operating assumption at many organizations that IT and security will assume responsibility only after a hire is completed.
CISA, AI tools, and the broader insider threat context
The report’s publication comes during National Insider Threat Awareness Month 2026 and shortly after a September 9 update from the US Cybersecurity and Infrastructure Security Agency (CISA). CISA’s update highlighted that malicious actors are using various AI tools to assist in applying for and obtaining remote IT jobs to gain privileged access into enterprises. The HYPR report also notes that the tactic of obtaining employment to gain access has been “extensively used by North Korean actors to gain employment in Western firms in recent years” for purposes such as data theft and extortion.
What this means for HR, IT/security, and policymakers
- HR: The survey found 98% of 500 US HR executives had experienced candidate fraud firsthand and 89% reported heightened concern about hiring fraud in the past two years. That combination of prevalence and rising worry places HR squarely in the center of pre‑hire identity risk decisions — reflected by the 53% of HR execs who say they own that risk before an offer.
- IT and security teams: Only 10% of respondents assigned pre‑offer responsibility to security and 7% to IT. HYPR’s framing — that many organizations assume IT/security take responsibility post‑hire — underscores a potential gap where technical controls and incident prevention may not be engaged until after credentials have been issued.
- Policymakers and national cyber agencies: CISA’s September 9 update and the timing during National Insider Threat Awareness Month 2026 tie the HYPR findings to a broader, government‑level concern about AI‑assisted applications and nation‑state tactics used to obtain insider access.
The study adds one more practical finding about resourcing: around 60% of identity verification and multi‑factor authentication budgets are reportedly authorized only reactively, after a security breach. That reactive posture, combined with the multi‑day average of unmonitored access and the high frequency of candidate fraud reported by HR leaders, frames the central challenge HYPR outlines: credentials are often authentic and issued by IT before fraud is detected, converting a hiring process into an attack vector.
HYPR’s study — dated September 15 and based on responses from 500 US HR executives — does not offer a single technical fix; instead it documents a pattern of timing, responsibility, and detection that organizations now face. The immediate questions the facts leave on the table are concrete: will identity‑verification and MFA funding shift from reactive to preventative models, and how will responsibility for pre‑hire identity assurance be redistributed across HR, talent teams, IT, and security? The answers will determine whether those average 5.73 days of unmonitored access shrink or persist.
Source: https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/




