Fraudulent hires are successfully obtaining corporate credentials and internal network access before detection in a growing number of cases, according to a new report by HYPR, as reported by Infosecurity Magazine.The report found that 42% of fraudulent candidates navigate pre-hire screening and assume their roles, with an average of 5.73 days of unmonitored access to corporate networks. This poses significant data security risks, especially as 98% of surveyed US HR executives have experienced candidate fraud. Adversaries can bypass network breaches by passing remote interviews and obtaining authentic credentials directly from IT. Screening and interviews remain the most common pre-hire detection points, with 68% of detected fraudulent candidates being identified by human instinct.This highlights a gap in security processes, with many organizations assuming IT and security teams only handle identity risk post-hire. The findings coincide with National Insider Threat Awareness Month, and an update to the US Cybersecurity and Infrastructure Security Agency's Insider Threat Mitigation Guide, which noted the use of AI tools by malicious actors to gain privileged access into enterprises. Despite these threats, approximately 60% of identity verification and multi-factor authentication budgets are authorized only after a security breach.Source: Infosecurity Magazine
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds

