Security2 publishers3 min readPublished
Human instinct caught 68% of pre-hire candidate fraud in HYPR's own survey
HYPR's September 15 survey of 500 US HR executives puts average unmonitored access for a fraudulent hire at 5.73 days, and the report's own detection figures undercut its chief executive's line about human intuition.
The Watch · Security desk

What happened
- Nearly all of the HR executives HYPR surveyed, 98%, said they had encountered candidate fraud first hand, and 89% said their concern had risen over the past two years.
- Fraudulent candidates clear pre-hire screening and take up the role in 42% of cases, according to the report.
- 98% of fraudulent hires already hold company credentials by the time post-hire fraud is detected, against the 96% of HR leaders who said their organization would catch it.
- CISA updated its Insider Threat Mitigation Guide on September 9, describing actors who use AI tools to apply for and obtain remote IT jobs with privileged access.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The entry path runs through the onboarding queue: a candidate who passes a remote interview is handed working credentials by IT, and the access stays live until a colleague or an audit flags the behaviour.
- cost Identity verification and MFA money is released after a breach in about 60% of cases, so the spending follows the incident.
- contradiction The two published accounts size the pre-credential gap differently, and a defender planning containment has to decide whether the window is a fortnight or a quarter.
- decision Buyers weighing identity proofing at onboarding are deciding on HR recollection, because the survey measures where staff say fraud was noticed and not how any control performed.
Among fraudulent candidates caught during the hiring process, 68% were identified by human instinct [8]. Screening accounted for 52% of pre-hire detections, interviews 45%, onboarding 42% and technical assessments 41% [9]. Companies logged an average of 2.2 checkpoints per fraud incident [10]. HYPR called that "a set of disconnected checks operating in silos" and wrote that "clearing an earlier stage offers no guarantee of identity assurance" [17][18].
"Human intuition is not a security control," HYPR chief executive and co-founder Bojan Simic said [15]. In his company's data it is the control catching most pre-hire fraud. Third-party security tools detected 53% of identity-based and AI-driven threats, and the other 47% surfaced through employee reports, internal audits and external alerts [11][12].
The credentials get issued after that. "Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT," Simic said [14]. Of the fraudulent hires who start work, 3% are identified on the day they are hired, 32% within one to three days, 45% within four to six days, and 20% run for up to three weeks [6]. Multiply the pass rate by that last share and 8.4% of all fraudulent candidates hold issued credentials for as long as three weeks [13].
The two published accounts of the report size the same gap differently. Help Net Security's write-up describes a 90-day period between hiring and onboarding as the blind spot [25]. The day counts reported by Infosecurity Magazine put the entire post-hire detection distribution inside three weeks [6].
The confidence and credential figures also count different populations. One is stated confidence across all 500 respondents [2]; the other describes only the hires found to be fraudulent after onboarding [4].
Ownership explains the timing. 53% of the HR executives said they own hiring identity risk before an offer is accepted, 19% assigned it to talent acquisition, 10% each to compliance and legal and to security, and 7% to IT [19]. HYPR said this suggests many organizations assume IT and security only take responsibility for candidate identity risk after the hire [20]. In the report's account, HR owns recruitment, IT and security step in once the new hire has access, and the period between the two belongs to no one [21]. Most companies then need one to three weeks to resolve a hiring fraud incident [22].
North Korean actors have used employment at Western firms for data theft and subsequent extortion in recent years, according to Infosecurity Magazine [24]. Simic said there are "vastly more fraudulent workers embedded in organizations than current data reflects" [16]. The survey records what 500 US HR executives report [2].
What to watch
- Whether HYPR publishes sector sample sizes and the question wording behind the 42% pre-hire pass rate.
- Whether CISA's updated Insider Threat Mitigation Guide turns identity proofing at onboarding into a contractor requirement.
- Any indictment that puts a counted number of embedded fraudulent workers against Simic's claim that there are vastly more than the data shows.