The majority of fraudulent hires receive corporate credentials and access to internal networks before companies discover they're fake, according to a new study by HYPR published September 15. Fraudulent job applicants successfully pass pre-hire screening and begin working in 42% of cases. The findings reveal that fake employees pose substantial data security threats during the days or weeks they operate undetected inside company systems.

Just 3% of fraudulent hires are caught on their official start date, while roughly one-third are discovered within one to three days, the report found. Another 45% are identified within four to six days, and 20% remain undetected for as long as three weeks. On average, fake employees have 5.73 days of unsupervised access to corporate networks. Nearly all HR executives surveyed—98% of the 500 US participants—said they'd personally encountered candidate fraud, while 89% reported growing worry about hiring fraud over the past two years. Among fraudulent candidates identified during hiring, 68% are spotted through human intuition. Screening catches 52%, interviews detect 45%, technical evaluations identify 41%, and onboarding reveals 42%.

"Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT," warned Bojan Simic, HYPR's CEO and co-founder. The report highlighted a major gap in how organizations assign responsibility for spotting candidate fraud before hiring. About half of HR executives—53%—said they own the responsibility for hiring identity risk before an offer goes out, while 19% pointed to talent acquisition teams, 10% to compliance or legal, 10% to security, and 7% to IT. The study noted that this pattern suggests many companies assume IT and security teams only become responsible for candidate identity risk after someone is hired. The report also described the detection process as "a set of disconnected checks operating in silos" rather than a proper security funnel, since no single stage reliably stops candidate fraud.

The findings arrive during National Insider Threat Awareness Month 2026, and they align with concerns raised by the US Cybersecurity and Infrastructure Security Agency. CISA released an updated Insider Threat Mitigation Guide on September 9 that described how malicious actors use AI tools to help them apply for and land remote IT positions, gaining privileged access to companies. North Korean actors have widely used this tactic in recent years to infiltrate Western companies for data theft and extortion. Despite these well-publicized dangers, around 60% of identity verification and multi-factor authentication budgets are only approved after a security breach has already occurred, the HYPR report found.

The reactive approach to security spending leaves organizations vulnerable during the critical window when fake employees have already received legitimate access but haven't yet been caught. Companies that wait for a breach before investing in identity verification may be allowing fraudulent insiders to operate freely for nearly a week on average, creating opportunities for data exfiltration, network reconnaissance, or credential harvesting that can enable future attacks. Organizations face a fundamental challenge in shifting security resources upstream to prevent fraudulent hires from entering the building in the first place, rather than scrambling to contain the damage after discovering an imposter already inside.