TL;DR: Candidate fraud has touched 98% of HR executives, while 68% of fraudulent hires are discovered only after human observation and intuition, and 98% have already received active corporate credentials before detection, according to HYPR research. The core issue is a broken onboarding-to-access handoff that leaves identity assurance, HR, and security operating on different timelines.
NHIMG editorial — based on content published by HYPR: Nearly All Fraudulent Hires Gain Active Corporate Credentials Before Detection, HYPR Research Finds
By the numbers:
- 68% of fraudulent hires are uncovered through human observation and intuition after bypassing initial screening.
- 98% of fake hires have already received active corporate credentials and internal network access before detection.
- Only 53% of enterprise identity-based attacks are caught by security tools, leaving 47% to manual discovery.
Questions worth separating out
Q: What breaks when fraudulent hires can receive credentials before detection?
A: The joiner lifecycle breaks.
Q: Why do candidate fraud cases become security incidents instead of HR issues?
A: Because the fraud does not stop at false paperwork.
Q: How can organisations detect onboarding fraud before access is granted?
A: Use layered verification that combines government document authentication, live biometric matching, and contextual risk signals from the application and interview process.
Practitioner guidance
- Insert a pre-access verification gate Block directory creation, SSO activation, and first-time entitlement assignment until candidate identity checks are complete and independently validated.
- Assign one owner for candidate-to-account handoff Document a single accountable workflow owner for the transition from hiring approval to credential issuance, including escalation when fraud signals appear.
- Instrument onboarding exceptions as control failures Track delayed verification, manual overrides, and post-day-one fraud discovery as measurable breakdowns in the joiner process.
What's in the full report
HYPR's full report covers the operational detail this post intentionally leaves for the source:
- Survey segmentation across HR, IT, and security respondents, including how confidence in fraud detection varies by role.
- The full breakdown of how fraudulent hires move from screening to active credentials across the employee lifecycle.
- Remediation timing and cost detail for organisations that spend weeks or months resolving a single fake hire.
- The companion passwordless identity assurance findings that underpin HYPR's broader identity fraud analysis.
👉 Read HYPR's report on HR identity fraud detection and access exposure →
Fake hires and onboarding gaps: what identity teams need to fix?
Explore further
Candidate fraud is now an identity lifecycle issue, not a recruitment anomaly. The article shows that fraudulent workers can pass hiring controls and still end up with active access before detection. That means the governing failure is not simply bad screening, but a broken joiner lifecycle where HR, IAM, and security do not share the same trust checkpoint. Practitioners should treat hiring fraud as an access governance event, not a standalone HR problem.
A few things that frame the scale:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs , Key Research and Survey Results.
- Only 20% of organisations have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
A question worth separating out:
Q: Who should be accountable when a fraudulent hire gets access?
A: Accountability should sit jointly with HR and security leadership because the control failure spans recruitment, identity proofing, and access governance. The practical answer is a shared decision path for offer, hire, and access issuance, with clear escalation when identity assurance is incomplete.
👉 Read our full editorial: Fraudulent hires often gain corporate access before detection