Fraudulent hires are reaching corporate access before detection across US organizations
Trend
Summary
Hide ▲
Show ▼
Fraudulent hires are reaching corporate credentials and internal network access before detection across US organizations, creating a measurable insider-risk window. In a sample of 500 US HR executives, 42% of fraudulent candidates successfully reached the hire stage and only 3% were caught on the same day. Detection usually occurred one to six days after hire, and 20% remained undetected for up to three weeks. The access gap leaves organizations exposed to data security risks and shows that hiring fraud can become an identity-assurance failure before IT is aware of it.
Related Happenings
North Korean fake-persona remote job infiltration campaign against Western tech companies
Campaign
H score34
First: 25.03.2026 17:30
Last: 25.03.2026 17:30
Sources 1
About this happening:
A North Korean fake-persona campaign is using remote job applications to gain trusted insider access at Western tech companies, creating theft and espionage risk....
North Korean fake-persona remote job infiltration campaign against Western tech companies
CampaignAbout this happening: A North Korean fake-persona campaign is using remote job applications to gain trusted insider access at Western tech companies, creating theft and espionage risk....
Rising insider risk and AI-enabled employee misuse across global organizations
Trend
H score17
First: 05.03.2026 18:00
Last: 05.03.2026 18:00
Sources 1
About this happening:
A 2026 survey found insider risk is rising across global organizations, increasing the chance of data theft, negligence-driven exposure, and misuse of AI product...
Rising insider risk and AI-enabled employee misuse across global organizations
TrendAbout this happening: A 2026 survey found insider risk is rising across global organizations, increasing the chance of data theft, negligence-driven exposure, and misuse of AI product...
Latest development: 09.09.2026 15:00
CISA released an updated Insider Threat Mitigation Guide that adds guidance for hybrid and remote work, AI used to manipulate or deceive, access control, visitor screening, and mitigating the risk of adverse employee separations, while emphasizing insider threats across physical and cyber threats.
Timeline
-
15.09.2026 18:15 1 articles · 2h ago
CISA updates Insider Threat Mitigation Guide for AI-assisted remote IT job fraud
Industry Or Public Sector UpdateCISA updated its Insider Threat Mitigation Guide after warning that malicious actors are using AI tools to help apply for and obtain remote IT jobs, a path that can lead to privileged access inside enterprises. The guidance also tied the tactic to North Korean actors using employment fraud for data theft and extortion.
Show sources
- Most Fraudulent Hires Receive Credentials Before Detection — www.infosecurity-magazine.com — 15.09.2026 18:15
-
15.09.2026 18:15 2 articles · 2h ago
Fraudulent hires receive corporate credentials before detection
Technical Analysis UpdateHYPR published findings showing that fraudulent candidates often pass pre-hire screening, receive corporate credentials and internal network access, and are then detected days later or not at all for up to three weeks. The study said 3% were caught the same day, 32% within one to three days, 45% within four to six days, and 20% remained undetected for up to three weeks, creating an average 5.73 days of unmonitored access to corporate networks.
Show sources
- Most Fraudulent Hires Receive Credentials Before Detection — www.infosecurity-magazine.com — 15.09.2026 18:15
- Most Fraudulent Hires Receive Credentials Before Detection — www.infosecurity-magazine.com — 15.09.2026 18:15