Fraudulent job candidates are slipping through remote hiring systems and gaining legitimate access to corporate networks, exposing a growing identity security gap that conventional screening tools are failing to close.
New research from HYPR found that 98% of surveyed HR executives have encountered candidate fraud. Yet 68% of fraudulent hires were ultimately exposed through human observation or intuition, rather than automated security controls.
The findings suggest generative AI, synthetic identities and voice-cloning technology are making it easier for impostors to navigate interviews, background checks and onboarding procedures. In 42% of organizations, the deception was not discovered until after the employee’s first day.

By then, the damage window was already open. HYPR found that 98% of fake employees detected after starting work had received active corporate credentials and access to internal systems. Organizations needed an average of four to six days to identify them.
“Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO and co-founder of HYPR. “Human intuition is not a security control. Sceptics might point to low reported numbers, but the lack of purpose-built verification technology means the industry is simply blind to the problem; there are vastly more fraudulent workers embedded in organizations than current data reflects.”
The HR-to-IT Handoff Creates a Security Gap
The vulnerability appears partly rooted in fragmented ownership. Before a new employee starts, HR leaders claim responsibility for identity risk in 53% of organizations, compared with 17% for IT and security teams. After credentials are issued, security and identity teams assume 55% of the responsibility while HR’s share drops to 15%.
That handoff creates a poorly monitored period in which a convincing synthetic candidate can become an authenticated insider.
The problem extends beyond hiring. Across enterprise identity attacks, automated identity management, endpoint security and threat-detection tools identified only 53% of incidents. The remainder surfaced through employee reports, internal audits or outside notifications.
Removing a fraudulent worker can also take far longer than detecting one. While impostors typically operated for nearly six days before discovery, remediation commonly required at least one to three weeks. Nearly one-quarter of organizations needed up to three months to resolve a single case.
Despite growing concern, security spending remains reactive. Approximately 60% of budgets for identity verification and multifactor authentication are approved only after a breach, according to HYPR.
The research points to a basic flaw in corporate zero-trust strategies: companies are scrutinizing what authenticated users do without reliably establishing who those users were in the first place.

