HYPR research found that hiring fraud is nearly universal among the HR leaders it surveyed, with 98% reporting encounters with candidate fraud even as 96% said they believed their organizations would catch it.
The bigger security concern is how those fraudulent hires are being found: 68% are ultimately uncovered through human observation and intuition after bypassing initial screening and automated controls.
Fraudulent candidates can go undetected for weeks
When fraudulent candidates bypass pre-hire detection, they are rarely caught quickly: less than 3% are flagged the same day, nearly a third take one to three days to surface, 45% require four to six days, and 20% go undetected for up to three weeks.
Threat actors have bypassed these systems by deploying generative AI, voice cloning, and synthetic profiles to infiltrate corporate payrolls.
Time between hiring and unboarding is a key gap for many employers
A key finding in the research is that an unmonitored 90-day window between hiring and onboarding, amplified by fragmented zero-trust controls across the employee lifecycle, is a significant blind spot for organizations.
Other key findings include:
- Prior to day one of onboarding, HR leaders claimed ownership of identity risk in 53% of survey responses, compared to just 17% for IT and security teams. Once credentials are created, accountability shifts toward security, and IAM assumes 73% of total ownership, while HR drops to 15% – allowing fake candidates to pass through corporate systems.
- Fraudulent hires average nearly six days of unmonitored access before discovery; resolving the incident takes one to three weeks. About 24% of organizations spend one to three months resolving a single fake hire, absorbing compounding costs across delayed timelines, backfill expenses, team disruption, and compliance exposure.
- Only 53% of all identity-based attacks are caught by third-party security tools.
- HR technology directors report below-average confidence in catching fraud. They take the longest of any group to identify a fraudulent hire.
- ~90% of HR leaders reported increased concern over hiring fraud, and approximately 60% of identity verification and MFA budgets are authorized reactively following a security breach.
“Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO and co-founder of HYPR. “Human intuition is not a security control. Skeptics might point to low reported numbers, but the lack of purpose-built verification technology means the industry is simply blind to the problem; there are vastly more fraudulent workers embedded in organizations than current data reflects.”
HYPR says that most organizations already possess the core capabilities to address candidate fraud but require a unified, continuous owner of identity across the points where HR, IT, and security currently hand it off to one another.
Hiring fraud creates an identity security opportunity for partners
For channel partners, the findings point to a security gap that extends beyond traditional endpoint and network defenses. HYPR found that responsibility for identity risk shifts significantly during the hiring process: HR leaders claimed ownership before onboarding in 53% of responses, while IAM assumes 73% of ownership once credentials are created.
That handoff can leave organizations without continuous oversight as a candidate moves from applicant to authenticated employee.
MSPs, MSSPs, identity specialists, and other security partners can use that gap to broaden customer conversations around identity beyond MFA and post-hire access management.
The research suggests an opportunity to help customers connect identity verification, onboarding, IAM, and ongoing monitoring into a more continuous security model—particularly as generative AI, voice cloning, and synthetic profiles make fraudulent candidates harder to identify through conventional screening alone.





