www.infosecurity-magazine.com 15 Sept 2026, 15:15 UTC

Fraudulent Job Candidates Gain Network Access Before Detection, Report Finds

Fraudulent Job Candidates Gain Network Access Before Detection, Report Finds
CyberSIXT Evidence Panel Source marked as original reporting

A HYPR report found that most fraudulent job candidates receive corporate credentials and internal network access before being identified. Based on a survey of 500 US HR executives, 42% of fraudulent candidates reportedly pass pre-hire screening and begin their roles. Only 3% are detected on their hiring day; 32% are found within one to three days, 45% within four to six days and 20% remain undetected for up to three weeks. HYPR calculated that this creates an average of 5.73 days of unmonitored network access.

Nearly all respondents (98%) said they had directly encountered candidate fraud, while 89% said concerns had increased over the previous two years.

Human judgement was the most common way of detecting fraudulent candidates, accounting for 68% of cases identified during recruitment. Screening detected 52%, interviews 45%, onboarding 42% and technical assessments 41%. HYPR said these checks often operate as disconnected processes, meaning that passing one stage does not establish identity assurance.

Responsibility was also unclear: 53% of HR executives said HR owned hiring identity risk before an offer, compared with 19% who named talent acquisition, 10% compliance or legal, 10% security and 7% IT.

The findings, published on 15 September 2026, come during National Insider Threat Awareness Month. The article links the issue to warnings from the US Cybersecurity and Infrastructure Security Agency about actors using AI tools to obtain remote IT jobs and gain privileged access, including activity attributed to North Korean operators. HYPR said roughly 60% of identity-verification and multi-factor-authentication budgets are approved only after a breach.

View full article

Article by CyberSIXT