Enterprise Identity Security Blind Spot: The 90-Day Hiring Fraud Gap
A new report from HYPR reveals a critical vulnerability in enterprise identity security: the 90-day window between hiring and onboarding, where fraudulent employees can gain legitimate access to corporate systems. According to CEO Bojan Simic, attackers no longer need to breach networks when they can pass remote interviews and obtain authentic credentials directly from IT. The lack of purpose-built verification technology means many fraudulent hires go undetected, leaving organizations exposed.
Fragmented Fraud Detection
While 98% of HR leaders have encountered candidate fraud, 96% believe their organizations would catch it. Yet when fraud slips through pre-hire checks, malicious actors receive credentials and network access before detection. Fraud is most commonly identified during screening, interviews, onboarding, or technical assessments averaging just 2.2 checkpoints per incident. Identity verification tools are often limited to specific events (e.g., account creation, sensitive transactions), leaving gaps where fraudulent hires operate undetected.
Recruitment platforms are beginning to integrate anti-fraud features, but third-party security tools detect only 53% of identity-based and AI-driven threats. The rest rely on manual discovery, such as employee reports or audits. Even in sectors with mandated automated controls, nearly half of threats depend on manual intervention.
Sector-Specific Confidence Gaps
Confidence in fraud detection varies by industry. IT and telecommunications, despite their technical capabilities, rely heavily on manual observation. Education shows the widest gap between concern and confidence, while manufacturing and utilities with in-person hiring practices report higher confidence. Sales, media, and marketing stand out as the only sector where confidence exceeds concern, leaning on employees to flag suspicious activity.
Ownership Gaps and Attacker Exploitation
Pre-hire identity risk ownership is often unclear in practice. HR typically handles recruitment, while IT and security take over once credentials are issued. The transition period between these stages lacks a defined owner, creating opportunities for attackers to embed themselves before detection. Even after hiring, fraud may only be discovered after credentials are already issued.
Costs and Reactive Responses
Resolving hiring fraud incidents takes one to three weeks, incurring financial and operational costs including delayed hiring, lost productivity, security risks, and compliance violations. By the time fraud is detected, 98% of malicious hires have already received company credentials. Organizations respond with an average of 2.52 measures per incident, such as implementing identity verification tools. However, identity security spending remains largely reactive, with 60% of investments triggered by breaches rather than proactive prevention.
Source: https://www.helpnetsecurity.com/2026/09/18/hypr-hiring-fraud-detection-report/
HYPR TPRM report: https://www.rankiteo.com/company/usehypr
"id": "use1789734393",
"linkid": "usehypr",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['IT',
'Telecommunications',
'Education',
'Manufacturing',
'Utilities',
'Sales',
'Media',
'Marketing'],
'type': 'Enterprise organizations (cross-industry)'}],
'attack_vector': 'Fraudulent hiring process (remote interviews, credential '
'issuance)',
'description': 'A critical vulnerability in enterprise identity security: the '
'90-day window between hiring and onboarding, where fraudulent '
'employees can gain legitimate access to corporate systems. '
'Attackers pass remote interviews and obtain authentic '
'credentials directly from IT, bypassing traditional network '
'breaches. The lack of purpose-built verification technology '
'means many fraudulent hires go undetected.',
'impact': {'financial_loss': 'Costs of resolving hiring fraud (1-3 weeks), '
'delayed hiring, lost productivity',
'legal_liabilities': 'Compliance violations',
'operational_impact': 'Delayed hiring, lost productivity, security '
'risks, compliance violations',
'systems_affected': 'Corporate networks, IT systems (via issued '
'credentials)'},
'initial_access_broker': {'entry_point': 'Fraudulent hiring process (remote '
'interviews)'},
'lessons_learned': 'Fraudulent hires exploit gaps in identity verification '
'during hiring/onboarding, particularly the 90-day window '
'between hiring and onboarding. Fragmented fraud detection '
'and unclear ownership of pre-hire identity risk create '
'vulnerabilities. Manual discovery methods are '
'insufficient, and reactive security spending dominates.',
'post_incident_analysis': {'corrective_actions': ['Adopt automated identity '
'verification tools for '
'hiring/onboarding',
'Define clear ownership of '
'pre-hire identity risk',
'Increase fraud detection '
'checkpoints beyond '
'screening and onboarding',
'Reduce dependency on '
'manual discovery'],
'root_causes': ['Lack of purpose-built identity '
'verification during '
'hiring/onboarding',
'Fragmented fraud detection with '
'limited checkpoints (avg. 2.2 per '
'incident)',
'Unclear ownership of pre-hire '
'identity risk between HR and '
'IT/security',
'Over-reliance on manual discovery '
'methods (e.g., employee reports, '
'audits)']},
'recommendations': ['Implement purpose-built identity verification technology '
'for hiring/onboarding',
'Close ownership gaps between HR, IT, and security teams '
'during the hiring process',
'Increase automated fraud detection to reduce reliance on '
'manual discovery',
'Proactively invest in identity security rather than '
'reacting to breaches'],
'references': [{'source': 'HYPR Report'}],
'regulatory_compliance': {'regulations_violated': 'Compliance violations '
'(unspecified)'},
'response': {'remediation_measures': ['Implementing identity verification '
'tools',
'Manual discovery (employee reports, '
'audits)'],
'third_party_assistance': 'Third-party security tools detect 53% '
'of identity-based and AI-driven '
'threats'},
'title': 'Enterprise Identity Security Blind Spot: The 90-Day Hiring Fraud '
'Gap',
'type': 'Identity Fraud / Insider Threat',
'vulnerability_exploited': 'Lack of purpose-built identity verification '
'during hiring/onboarding, fragmented fraud '
'detection, unclear ownership of pre-hire identity '
'risk'}