HYPR Releases New Study Highlighting Prevalence of Fraudulent Workers and Identity Security Risks

For years, enterprise security teams have focused on stopping attackers from stealing employee credentials. A growing form of identity fraud presents a different problem: what happens when an attacker persuades the company to issue legitimate credentials to them?

Research released by HYPR suggests fraudulent workers are routinely getting through corporate hiring processes and gaining access to internal systems before organizations recognize the deception.

Ninety-eight percent of HR executives surveyed said they have encountered candidate fraud. Among fraudulent workers who make it through the hiring process, 98% receive active corporate credentials before being detected.

Rather than exploiting a software vulnerability or stealing an existing account, these attackers can use synthetic profiles, generative AI and voice-cloning technology to impersonate legitimate candidates, complete interviews and enter an organization through its normal onboarding process.

That effectively turns the hiring process into an identity security boundary.

“For 42% of organizations, hiring fraud is detected only after the employee’s first day, with detection taking an average of four to six days,” according to HYPR’s findings.

Perhaps the most striking weakness is how those impostors are eventually caught. Sixty-eight percent are identified through human observation and intuition rather than automated security controls.

“Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO and co-founder of HYPR. “Human intuition is not a security control.”

That dependence on manual discovery reflects a broader problem with enterprise identity security. Across identity-based attacks generally, HYPR found automated tools catch only 53% of incidents. Another 22% are uncovered following reports from coworkers, 15% through internal audits and 10% through external notifications.

The research also identifies a significant organizational gap between HR and security.

Before an employee starts, 53% of HR leaders say their function owns identity risk, compared with only 17% of IT and security teams. Once credentials are provisioned, responsibility abruptly shifts: security and IAM teams claim 55% of the risk, compared with 15% for HR.

An attacker who can successfully navigate that transition may therefore move from being an unverified candidate to a trusted corporate identity without any single team maintaining responsibility for identity assurance throughout the process.

The difficulty does not end when the fake employee is identified. Remediation typically requires at least one to three weeks, and nearly a quarter of organizations say resolving a single fraudulent hire can take between one and three months.

Organizations appear to recognize the growing risk. Nearly nine in 10 HR leaders report increased concern about hiring fraud. But spending remains heavily reactive, with roughly 60% of identity verification and MFA budgets authorized only after a security breach.

The findings combine a 2026 HYPR survey of 500 U.S. HR leaders across talent acquisition, HR operations and HR technology with the company’s 2026 State of Passwordless Identity Assurance Report, produced with S&P Global / 451 Research and based on 950 IT security decision-makers across the U.S., EMEA and APAC.

The emerging lesson is that identity assurance cannot be limited to authentication after somebody joins an organization. If attackers can manufacture a convincing candidate and persuade an employer to grant them legitimate access, the distinction between hiring fraud and a cybersecurity breach effectively disappears.

Join our LinkedIn group Information Security Community!

No posts to display