Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response Why do remote work and shared credentials increase…
Threats, Abuse & Incident Response

Why do remote work and shared credentials increase identity fraud risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Threats, Abuse & Incident Response

Remote work makes it easier for one person to hand over login credentials and one-time codes to someone else without ever meeting face to face. That breaks the assumption that a background-checked employee is always the person using the account. Shared access expands exposure to insider fraud, subcontracting, and unauthorized third parties who were never vetted.

Why This Matters for Security Teams

Remote work and credential sharing turn identity from a controlled authentication event into a trust problem that can be passed across chat apps, personal devices, and unmanaged locations. That matters because identity fraud usually succeeds when the organisation assumes the person at login is still the vetted employee behind the account. Once one-time codes, session cookies, or shared passwords circulate, the account can be used by a subcontractor, family member, or fraud ring with no reliable way to distinguish them.

For security teams, the risk is not just account takeover. It is the collapse of attribution, approval chains, and non-repudiation across the full access path. NHIMG’s 2024 Non-Human Identity Security Report found that 23.7% of organisations share secrets through insecure methods such as email or messaging applications, which is a strong indicator that informal access habits persist when work is distributed. Current guidance from the NIST Cybersecurity Framework 2.0 and the OWASP Non-Human Identity Top 10 both point toward stronger identity lifecycle control, but the real issue is behavioural: shared access makes fraudulent use look ordinary in logs. In practice, many security teams discover identity fraud only after an access review or payroll investigation, rather than through intentional detection.

How It Works in Practice

Remote work increases fraud risk because the usual physical and procedural checks disappear. In a shared office, misuse may be noticed through badge access, desk conversations, or visible device handoff. In remote settings, the same credential can be reused by someone else without any environmental signal. When credentials are shared, the organisation loses the ability to bind access to a single accountable identity, which undermines MFA, conditional access, and incident response.

Practical controls start with reducing shared secrets and replacing them with unique, per-person access. That means each worker gets their own account, their own MFA factor, and their own device posture, even when they support the same process. It also means avoiding reusable secrets for high-risk systems and using stronger identity proofing for recovery. The NIST SP 800-53 Rev 5 Security and Privacy Controls supports account management, auditability, and least privilege, while NHIMG’s Ultimate Guide to NHIs is useful for understanding why credential sprawl and informal sharing create durable exposure.

  • Assign unique accounts to every worker, contractor, and third party.
  • Disable credential sharing for production and financial systems wherever possible.
  • Use MFA that resists replay and discourages code forwarding.
  • Shorten session lifetimes and review high-risk logins for location, device, and time anomalies.
  • Require documented approval for delegated access, with explicit start and end dates.

Where organisations need shared operational access, current best practice is to use group-based entitlements with individual authentication, not one shared login. These controls tend to break down in contractor-heavy environments with weak joiner-mover-leaver discipline because access changes are often handled informally after work has already started.

Common Variations and Edge Cases

Tighter access control often increases friction for distributed teams, requiring organisations to balance fraud reduction against operational speed. That tradeoff is especially visible in customer support, shift work, and outsourced operations, where managers may argue that sharing credentials is the fastest way to keep work moving. Current guidance suggests the safer path is not shared authentication, but delegated authority with strong audit trails.

There are also edge cases where fraud risk changes rather than disappears. Bring-your-own-device programs, travel-heavy roles, and multilingual support desks can all increase identity ambiguity if device trust, location signals, and escalation paths are weak. Recovery flows are another weak point: if account recovery relies on email links or easily forwarded codes, an attacker does not need to defeat the primary login. NHIMG’s Guide to the Secret Sprawl Challenge shows how quickly insecure sharing expands exposure once secrets begin moving through ordinary collaboration tools.

For organisations with mature identity programs, the important distinction is between legitimate delegation and unauthorised impersonation. That distinction is only defensible when each action is attributable to an individual, each approval is logged, and shared operational credentials are eliminated or tightly scoped. In environments with high contractor turnover, fragmented HR records, or weak offboarding, the guidance breaks down because nobody can prove who actually used the account at the moment of fraud.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Identity proofing and access control are central to preventing shared-credential fraud.
OWASP Non-Human Identity Top 10NHI-01Shared secrets and poor secret handling are core NHI fraud enablers.
NIST SP 800-63IAL2Stronger identity proofing helps prevent impersonation in remote and recovery flows.
CSA MAESTROTRUST-04Delegated access and accountability are key for distributed, autonomous operations.
NIST AI RMFRisk governance should account for identity ambiguity and misuse in remote work.

Give each user unique access and verify entitlement before granting any sensitive account.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on August 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org