Jessica Entwistle
September 16 2026
A new report from Infosecurity Magazine highlights a significant and growing insider threat challenge: the majority of fraudulent job candidates are successfully hired and receive corporate credentials, system access and sensitive data before their deception is detected. The report, based on research into hiring fraud trends, found that attackers are using increasingly sophisticated methods to pass background checks, fake references and identity verification processes. In many cases, fraudulent hires gain access to email, collaboration tools, customer data and internal systems before red flags are raised. The report warns that this trend presents a serious risk to organisations, as these individuals may be working on behalf of criminal groups, nation-state actors or competitors seeking to steal intellectual property, conduct espionage or facilitate ransomware attacks.
For UK organisations, this is a reminder that insider threat does not only come from disgruntled employees or accidental mistakes. It can also come from individuals who were never legitimate employees in the first place. The operational challenge is that traditional hiring processes, particularly in remote or hybrid work environments, may not be sufficient to detect sophisticated identity fraud. Once a fraudulent hire has credentials, they have the same access as any other employee, and their activity may not trigger immediate suspicion. The risk is compounded in organisations with rapid hiring cycles, high turnover, or reliance on contractors and third-party workers. The report underscores the need for stronger identity verification, continuous monitoring of user behaviour, and clear processes for revoking access quickly when concerns are raised. Organisations that do not have robust onboarding security, least-privilege access controls or insider threat monitoring programmes may be particularly vulnerable to this type of attack.
Organisations should review hiring and onboarding processes, particularly for remote workers, contractors and roles with access to sensitive systems or data. Consider whether identity verification is robust enough, whether background checks are being conducted by trusted providers, and whether reference checks are being validated properly. Review whether access is granted on a least-privilege basis, with clear approval processes and time-limited access for contractors or temporary workers. Consider whether user behaviour analytics or insider threat monitoring tools are in place to detect unusual activity after someone is hired, such as bulk data downloads, access to systems outside their role, or unusual login patterns. Ensure that offboarding processes are clear and consistently followed, with access revoked promptly when someone leaves the organisation or when concerns are raised. Review whether HR, IT and security teams have clear communication channels and defined responsibilities for managing insider threat risk. For organisations with remote or hybrid workforces, consider whether additional identity verification measures such as video interviews, document verification or in-person onboarding are appropriate for high-risk roles.
Source: Infosecurity Magazine