AGP Picks
View all

Nearly All Fraudulent Hires Gain Active Corporate Credentials Before Detection, HYPR Research Finds

HR and security leaders reveal over two-thirds of fake workers are caught by "gut feeling" after bypassing traditional onboarding defenses

NEW YORK, Sept. 15, 2026 (GLOBE NEWSWIRE) -- Ninety-eight percent of HR executives have encountered candidate fraud, yet automated security controls fail to intercept these attempts, according to new research released today by HYPR, the Identity Assurance Company. Instead, 68% of fraudulent hires are uncovered through human observation and intuition after bypassing initial screening, as threat actors deploy generative AI, voice cloning, and synthetic profiles to infiltrate corporate payrolls.

The research combines insights from HYPR’s new State of HR Identity Fraud Detection report with its 2026 State of Passwordless Identity Assurance Report. The findings reveal a critical security blind spot: an unmonitored 90-day window between hiring and onboarding, amplified by fragmented zero-trust controls across the employee lifecycle.

For 42% of organizations, hiring fraud is detected only after day one of employment - taking an average of four to six days to uncover, by which time 98% of fake hires have already received active corporate credentials and internal network access. This delay stems from a broader automation breakdown with traditional security controls consistently failing to intervene. In fact, across all enterprise identity-based attacks, automated tools catch barely half of threats (53%)—leaving the remaining 47% to manual discovery through coworker reports (22%), internal audits (15%), and external notifications (10%)1.

“Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO and co-founder of HYPR. “Human intuition is not a security control. Sceptics might point to low reported numbers, but the lack of purpose-built verification technology means the industry is simply blind to the problem; there are vastly more fraudulent workers embedded in organizations than current data reflects.”

Key Findings:

  • The Ownership Void: Prior to day one, onboarding, HR leaders claim ownership of identity risk in 53% of surveyed responses, compared to just 17% of IT and security teams. Once credentials are created, accountability flips. Security and IAM claim 55% of the risk, while HR drops to 15%. This unmonitored transition allows synthetic candidates to pass directly onto corporate systems.
  • The Remediation Timeline: While fraudulent hires average nearly six days of unmonitored access before discovery, resolving the incident takes a minimum of one to three weeks. Nearly a quarter (24%) of organizations spend one to three months fully resolving a single fake hire, absorbing compounding costs across delayed timelines, backfill expenses, team disruption, and compliance exposure.
  • Accidental Detection Is an Enterprise-Wide Vulnerability: Accidental discovery is not unique to HR. Across all identity-based attacks, where automated controls like IAM, SIEM, and EDR are mandated, only 53% of threats are caught by security tools.
  • Technical Skepticism: The leaders closest to enterprise identity infrastructure express the lowest confidence in current defenses. HR technology directors report below-average confidence in catching fraud (41% vs. 53% across all HR leaders surveyed) and average eight days to uncover an impostor. Concurrently, 51% of IT teams rely on coworker reports to identify fraudulent hires.
  • Reactive Budget Allocations: Nearly 90% of HR leaders report heightened concern over hiring fraud, yet enterprise security investment remains post-incident. Approximately 60% of identity verification and MFA budgets are authorized reactively following a security breach2.

About the Research

The findings combine two independent studies: a survey of 500 U.S. HR leaders across Talent Acquisition, HR Operations, and HR Technology conducted by HYPR in 2026, alongside HYPR’s 2026 State of Passwordless Identity Assurance Report, produced with S&P Global / 451 Research, which surveyed 950 global IT security decision-makers across the U.S., EMEA, and APAC.

To download the full reports, visit HYPR.com/Reports.

About HYPR

HYPR, the Identity Assurance Company, helps organizations create trust in the identity lifecycle. The HYPR solution provides the strongest end-to-end identity security, combining modern passwordless authentication with adaptive risk mitigation, automated identity verification and a simple, intuitive user experience. With a third-party validated ROI of 324%, HYPR easily integrates with existing identity and security tools and can be rapidly deployed at scale in the most complex environments.

Media Contact:
Fabienne Dawson
fabienne@hypr.com
917.374.6860

1 HYPR 2026 State of Passwordless Identity Assurance Report
2 HYPR 2026 State of Passwordless Identity Assurance Report

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/39784a16-ebef-4d6e-8c99-f8ef4f6e8638


Primary Logo

HYPR State of HR Identity Fraud Detection

HYPR releases its new research report following a survey of 500 U.S. HR leaders across Talent Acquisition, HR Operations, and HR Technology

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Jobs & Careers Watch

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.