By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Artemis SecurityPublished August 5, 2026

TL;DR: A new hire’s account signed in from Belarus, Russia, and the US while Okta risk scores stayed at MEDIUM and every login succeeded, showing how identity fraud can hide inside legitimate onboarding and shared VPN traffic, according to Artemis Security. The case proves anomaly detection needs cross-log correlation because accounts compromised from day one have no trustworthy baseline to compare against.


At a glance

What this is: This is an identity fraud case study showing that a newly provisioned employee account was operated from multiple geographies for 18 days without triggering automated containment.

Why it matters: It matters because IAM, IGA, and SOC teams often rely on post-provisioning behaviour and risk scores that fail when fraud begins at account creation and blends into legitimate access.

By the numbers:

👉 Read Artemis Security's analysis of the new-hire identity fraud case


Context

New-hire identity fraud is a governance failure as much as a detection failure. A newly issued account can look legitimate at the directory level while being operated by someone other than the person HR thinks it hired, especially when access is granted broadly during onboarding and sign-ins are allowed through shared VPN infrastructure.

The core problem is that anomaly detection assumes a stable baseline that can be violated. When the identity is compromised from day one, there is no clean history to compare against, so the account can look normal even while it is being used from multiple countries and multiple devices.


Key questions

Q: What breaks when a new hire is compromised before the first login baseline exists?

A: Baseline anomaly detection loses most of its value because there is no trusted pre-compromise pattern to compare with. Security teams should rely on account age, source geography, factor mix, device enrollment, and access breadth together, not on login scoring alone. A fresh identity can look normal while already being controlled by the wrong person.

Q: Why do mixed MFA factor types matter in remote-worker fraud cases?

A: They expose operator mismatch. If one geography succeeds with hardware-backed factors while another relies on passwords, security questions, or emulated push, the enrolled device and the remote operator are not the same entity. That should trigger investigation across IAM, HR, and the SOC because the account may be legitimate only on paper.

Q: How do security teams detect scripted login behaviour inside legitimate VPN traffic?

A: Look for repeated session starts at the exact same second across many hours, then compare those patterns with geography, device fingerprint, and account age. Human use jitters; scripts do not. Precision timing inside a corporate VPN is often a camouflage mechanism, especially when it coexists with foreign access.

Q: Who is accountable when a fraudulent employee is onboarded?

A: Accountability is shared between HR, which owns hiring assurance, and identity teams, which own downstream access governance. If either side treats the process as someone else’s problem, the organisation can end up issuing valid access to an invalid identity. Shared controls are the only reliable answer.


Technical breakdown

Why baseline anomaly detection fails on day-one account compromise

Baseline models depend on prior behaviour. They look for change, not intent, so they work best when an account has a history of normal use before the attack starts. In a fresh hire fraud case, the attacker controls the account as soon as it exists, which means there is no trusted pre-compromise pattern to compare with. Even when location, device, and factor mix are strange, those signals may be scored individually rather than interpreted as a single fraud hypothesis.

Practical implication: fuse directory age, source geography, factor type, and device enrollment into one triage view for new accounts.

How device-bound factors expose operator mismatch

Device-bound MFA factors, such as hardware-backed sign-ins, are tied to a specific enrolled device, while knowledge factors can be used anywhere a person can obtain them. When one geography consistently uses device-bound factors and another only succeeds with passwords, security questions, or emulated mobile push, the factor mix becomes evidence of split control. That is a cryptographic clue, not just a behavioural one, because the enrolled hardware and the remote operator are no longer the same entity.

Practical implication: review successful MFA by source IP and flag any location that never uses the enrolled device.

Why fixed-second logon timing is a script tell, not human behaviour

Humans vary by seconds and minutes; scripted keepalives do not. Repeated session starts at an exact second past the hour often indicate an automation pattern designed to preserve legitimacy, keep sessions alive, or mask an off-hours operator. In this case, the metronomic timing mattered because it coexisted with foreign sessions, which turns what could be dismissed as coincidence into a deliberate control of the login pattern.

Practical implication: build timing analytics that aggregate session starts by second-of-hour and alert on repeated precision.


Threat narrative

Attacker objective: The objective was to sustain fraudulent remote-worker access long enough to operate as a legitimate employee and preserve access to business systems.

  1. Entry occurred through a legitimate new-hire onboarding flow, where the account was provisioned with broad access and used from a US VPN path as soon as it was created.
  2. Escalation took the form of multi-operator abuse, with Belarus, US, and Russian access patterns using different factor types and a scripted VPN keepalive to preserve legitimacy.
  3. Impact was broad enterprise reach across Office 365, HR, payroll, and expense systems before the account was finally deactivated.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
  • Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Day-one compromise destroys the usefulness of baseline-driven anomaly models. Anomaly detection assumes an account has stable history before the break. That assumption fails when the identity is fraudulent from creation, because every sign-in is already part of the attack. The implication is that identity programmes need a separate new-account fraud lens, not just better scoring thresholds.

Factor asymmetry is the clearest cryptographic clue in remote-worker fraud. When device-bound authentication appears only in one geography and weaker knowledge-based factors appear in another, the factor mix reveals who actually holds the hardware. This is not a generic MFA issue, it is an operator-mismatch problem that crosses IAM, HR onboarding, and SOC investigation. Practitioners should treat source-based factor analysis as evidence, not background noise.

Metronomic session timing is a governance signal, not a curiosity. A fixed login cadence usually means something is being automated to preserve the appearance of normal work. That pattern is especially dangerous when it sits inside an otherwise legitimate employee identity, because it lets a scripted session hide inside ordinary enterprise VPN traffic. Security teams need timing analytics that look across hours, not isolated events.

New-hire access reviews need to focus on the first 30 days, not the first recertification cycle. The identity was provisioned legitimately, then used fraudulently before conventional review windows could matter. That creates a lifecycle blind spot where HR, IAM, and SOC all see partial truth. The governance lesson is that onboarding is now a threat surface, not just an administrative process.

Access provisioning without identity verification creates a false sense of legitimacy. The account had real credentials, real MFA, and real access, so every system downstream treated it as trusted. The control gap was not missing authentication, it was trusting the provisioning process to establish the right human behind the account. Practitioners should redesign onboarding controls around operator assurance, not just account creation.

From our research:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.
  • The 2026 NHI Lifecycle Management Guide is the next step if you need to map onboarding, rotation, and offboarding controls to this kind of identity failure.

What this signals

Day-one identity fraud is a lifecycle problem before it is a detection problem. If an organisation can issue access without validating who is actually operating the account, the security stack inherits an identity that is already compromised. The right response is to harden the first 30 days of every account lifecycle and align review triggers with onboarding risk, not calendar recertification.

Operator mismatch should become a standard triage concept. When factor use, geography, and device enrollment split cleanly across a single account, the question is no longer whether the login is successful. The question is whether the identity belongs to the person who was hired, and that distinction belongs in IAM case management, SOC hunting, and HR verification workflows.

New-hire fraud exposes a wider truth about identity governance: legitimacy at provisioning is not proof of legitimacy in use. As access expands across Office 365, HR, payroll, and finance systems, the blast radius grows faster than most review cycles can react. Teams should expect to combine identity lifecycle controls with behavioural analytics and endpoint evidence in the same operating model.


For practitioners

  • Correlate MFA factor type by source geography Group successful sign-ins by IP, country, and factor class so device-bound authentication, push approvals, and knowledge factors can be compared for the same account. The strongest fraud signal is a geography that never uses the enrolled device while another geography does. Use the device enrollment record as the reference point.
  • Add new-account fraud checks to day-zero and day-30 reviews Review every account under 30 days old for source country drift, login regularity, and unusually broad access grants. Pair IAM review with HR verification for remote hires whose only device is unmanaged, virtual, or absent from EDR and MDM.
  • Alert on recurring login precision at the second level Build detections that aggregate session starts by second-of-hour and flag identities that repeat the same timestamp across many hours. Fixed :MM:SS patterns are strong indicators of scripted keepalives or human-in-the-loop automation masking off-hours control.
  • Treat active access without managed endpoints as a fraud signal If a new employee has live access to HR, payroll, or finance systems but no managed endpoint telemetry, escalate for manual review before additional entitlements are granted. Cloud-hosted virtual desktops and personal devices should not be assumed to prove physical presence.

Key takeaways

  • This case shows that an account can be fully legitimate at issuance and still be fraudulent from its first use.
  • The evidence came from timing, geography, and factor asymmetry, not from a single risk score or one suspicious login.
  • The control gap is early lifecycle assurance: onboarding, MFA, and access review all have to validate the operator, not just the account.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The case shows onboarding trust and identity verification gaps for non-human-style lifecycle abuse.
NIST CSF 2.0PR.AC-1Identity and credential issuance are central to the provisioning failure described here.
NIST SP 800-53 Rev 5IA-2Authentication and identity proofing failures are part of the attack path.
NIST Zero Trust (SP 800-207)Zero Trust assumes continuous verification, which this case bypassed through legitimate access.
MITRE ATT&CKTA0003 , Persistence; TA0006 , Credential AccessThe account relied on staying active and using valid credentials across multiple sessions.

Map new-account fraud checks to NHI onboarding controls and verify operator identity before broad access is granted.


Key terms

  • New-Hire Identity Fraud: A fraud pattern where a newly provisioned account is controlled by someone other than the person the organisation believes it hired. It often blends into legitimate onboarding, making directory status and successful authentication misleading without cross-checking geography, devices, and factor use.
  • Factor Asymmetry: A mismatch in the type of authentication factors used across different source locations or devices for the same identity. In practice, it can show that one operator holds the enrolled hardware while another relies only on knowledge-based or emulated factors.
  • Operator Mismatch: A condition where the person behind an authenticated session is not the person the organisation intended to grant access to. It matters because account success, MFA success, and active directory status can all be true while the wrong human is using the identity.
  • Baseline-Free Compromise: A compromise that begins before the account has any trustworthy historical behaviour. Conventional anomaly detection struggles here because there is no pre-attack pattern to compare against, so the identity appears normal until contextual signals are correlated.

What's in the full article

Artemis Security's full article covers the operational detail this post intentionally leaves for the source:

  • The full session timeline with per-event log excerpts from Okta, VPN, and MFA records.
  • The manager observation trail and analyst workflow that turned suspicion into a confirmed case.
  • The account-specific identity evidence showing which factor types mapped to which geographies.
  • The exact containment sequence used after the account was validated as fraudulent.

👉 Artemis Security's full article covers the session evidence, factor asymmetry, and containment path.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org