Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

New-hire identity fraud: why conventional detection missed it


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: A new hire’s account signed in from Belarus, Russia, and the US while Okta risk scores stayed at MEDIUM and every login succeeded, showing how identity fraud can hide inside legitimate onboarding and shared VPN traffic, according to Artemis Security. The case proves anomaly detection needs cross-log correlation because accounts compromised from day one have no trustworthy baseline to compare against.

NHIMG editorial — based on content published by Artemis Security: a new-hire identity fraud case involving multi-country access and MFA abuse

By the numbers:

Questions worth separating out

Q: What breaks when a new hire is compromised before the first login baseline exists?

A: Baseline anomaly detection loses most of its value because there is no trusted pre-compromise pattern to compare with.

Q: Why do mixed MFA factor types matter in remote-worker fraud cases?

A: They expose operator mismatch.

Q: How do security teams detect scripted login behaviour inside legitimate VPN traffic?

A: Look for repeated session starts at the exact same second across many hours, then compare those patterns with geography, device fingerprint, and account age.

Practitioner guidance

  • Correlate MFA factor type by source geography Group successful sign-ins by IP, country, and factor class so device-bound authentication, push approvals, and knowledge factors can be compared for the same account.
  • Add new-account fraud checks to day-zero and day-30 reviews Review every account under 30 days old for source country drift, login regularity, and unusually broad access grants.
  • Alert on recurring login precision at the second level Build detections that aggregate session starts by second-of-hour and flag identities that repeat the same timestamp across many hours.

What's in the full article

Artemis Security's full article covers the operational detail this post intentionally leaves for the source:

  • The full session timeline with per-event log excerpts from Okta, VPN, and MFA records.
  • The manager observation trail and analyst workflow that turned suspicion into a confirmed case.
  • The account-specific identity evidence showing which factor types mapped to which geographies.
  • The exact containment sequence used after the account was validated as fraudulent.

👉 Read Artemis Security's analysis of the new-hire identity fraud case →

New-hire identity fraud: why conventional detection missed it?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Day-one compromise destroys the usefulness of baseline-driven anomaly models. Anomaly detection assumes an account has stable history before the break. That assumption fails when the identity is fraudulent from creation, because every sign-in is already part of the attack. The implication is that identity programmes need a separate new-account fraud lens, not just better scoring thresholds.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.

A question worth separating out:

Q: Who is accountable when a fraudulent employee is onboarded?

A: Accountability is shared between HR, which owns hiring assurance, and identity teams, which own downstream access governance. If either side treats the process as someone else’s problem, the organisation can end up issuing valid access to an invalid identity. Shared controls are the only reliable answer.

👉 Read our full editorial: Identity fraud detection failed when a new hire had no baseline



   
ReplyQuote
Share: