Skip to main content

Sep 3, 2026

Your ATS Is Now Part of Your Attack Surface

The attack that should worry your security team most this quarter didn't start with a phishing email. It started with a job application.

Key Insights

Recently, Abnormal's threat intelligence team flagged roughly 3,500 fraudulent personas attempting to enter organizations through hiring

Your ATS is a high-value, externally exposed system security rarely watches—both a data target and an entry point for fraudulent hires.

Standard hiring controls can't catch a fraudulent identity built on a real, stolen one—they were never designed to.

Your ATS Is Now Part of Your Attack Surface

In August 2026, the Wall Street Journal traced a North Korean remote-worker cell that had infiltrated at least eight U.S. companies in a matter of months, part of a scheme that U.S. authorities estimate moves hundreds of millions of dollars a year to the regime's sanctioned weapons programs. 

Days earlier, the FBI confirmed that one of these workers had reached a U.S. federal agency, and on July 31st, eleven allied governments issued a joint alert on the same threat. 

For a decade, the most dangerous thing in your inbox was a well-crafted email. Today, it can be a well-crafted identity. These operatives didn't break in. They were legitimately hired and walked through the front door with valid credentials, multi-factor authentication, and corporate access from their first day.

When the attack starts with a job application instead of a phishing email, your onboarding pipeline now becomes part of your security perimeter. In 2026, that perimeter includes the org chart, and the system at the front of it is one security almost never looks at.

This piece walks through why the applicant tracking system (ATS) has quietly become part of your attack surface, what the fraudulent-hire threat actually looks like, and where security and HR can close the gap together before an account is ever provisioned. 

A System Built to Receive Files From Anyone

Most security awareness training reduces to a single rule: don't open attachments from people you don't know. Recruiting can't follow it, because opening files from strangers is the entire job, and the people doing it are measured on speed rather than suspicion.

An ATS exists to take in résumés, personal data, file uploads, and messages from people you've never met, all day, on purpose. It's among the largest and most sensitive externally facing systems a company runs, and yet it's usually administered by recruiting, evaluated by HR, and invisible to security until something goes wrong. That combination of high exposure and low visibility is what makes it an attack surface, and it raises questions most security teams have never had to answer:

  • When your ATS receives a résumé from a stranger, who inspects that file the way you'd inspect an inbound email attachment?

  • If your ATS vendor left candidate data exposed tomorrow, would your security team even know that data was in scope?

  • A fraudulent candidate who wants access inside your company has to make first contact somewhere, and that somewhere is your ATS.

Attackers have built campaigns around exactly that gap. The group tracked as FIN6 has posed as job seekers to target recruiters, delivering malware through résumé files and fake candidate sites engineered so that automated analysis sees only harmless content. The résumé becomes the payload, aimed at the one team whose job requires them to open it.

A Concentration of Sensitive Data No One Calls Sensitive

An ATS also accumulates the personal data of everyone who has ever applied: names, home addresses, phone numbers, work history, and sometimes government identifiers, often millions of records built up over years in a single third-party system.

In 2025, researchers at Cybernews found a misconfigured cloud storage container belonging to the recruiting platform TalentHook that exposed nearly 26 million résumés, with no exploit and no malware involved, just a storage bucket left open.

Because an ATS is third-party software wired into your environment, its security posture is effectively yours and its breach is your candidates' exposure. Yet these systems are usually bought through HR procurement, where no one is evaluating cloud posture or integration permissions the way security would for any other vendor holding this much sensitive data.

Meet Infiltration Prevention

Abnormal's behavioral AI reads the signals across Workday and Greenhouse, your identity providers, and email to catch synthetic personas and nation-state operators as they apply, handing your SOC the intelligence that standard hiring and security screening miss, well before access is ever granted. 

in-line_cta_for_DPRK.png

Where the Fraudulent Identity Gets In

The ATS is a data target and a malware vector, and it's also the front door for a fraudulent hire. That's where the current headlines stop being someone else's problem.

The organizational blind spot makes these attacks so successful. One team confirms that an identity document is real, another secures the network, and neither confirms the document belongs to the person behind it. A fraudulent persona slips through that seam and, once granted access, blends in like any other authorized user. It's the same background-check blind spot these campaigns are built to exploit.

This is neither rare nor limited to one country. A 2025 Justice Department case against an Arizona "laptop farm" operator tied 68 stolen U.S. identities to more than 300 companies, moving over $17 million in roughly three years. The same playbook now runs well beyond any single nation-state: fraudulent hiring isn't just a North Korea problem, but it has surfaced across finance, healthcare, defense, crypto, manufacturing, retail, and education.

Over the past 18 months, Abnormal's threat intelligence team has flagged roughly 3,500 fraudulent personas attempting to enter organizations through hiring and investigated about 1,000 more, spanning DPRK operatives and personas that show indicators consistent with other nation-state and organized fraud networks

In at least two of those cases, Abnormal observed it live: the person on the interview call was likely a U.S. citizen operating a DPRK-linked persona, with legitimate identification and native fluency, and nothing for a deepfake detector to catch.

Because Abnormal correlates these signals across its customer base, reused infrastructure, shared IP ranges, and repeated résumé templates, a persona that looks unremarkable to any single company surfaces as part of a known campaign, and it can be caught before access is ever granted rather than after. 

Every one of those attempts began the same way, as an application, which means the impersonation starts at the top of the funnel, inside the ATS, long before an account is provisioned or a laptop ships.

Protect Your Organization and ATS

Your asset inventory almost certainly doesn't list the ATS, and it should. It's externally facing, data-rich, integration-heavy, and administered outside your team, exactly the profile of a system that belongs in your third-party risk process and your monitoring strategy.

The goal isn't to slow hiring down or add suspicion to the process; it's to close the security gap between identity provisioning and network access, where point tools and manual checks tend to leave one. Infiltration Prevention routes a sourced evidence brief to your security team for review and is designed not to take any automated employment action, so the hiring decision stays with the people who own it.

Abnormal AI builds behavioral AI that protects email, identity, and AI systems, and stops insider threats, including the fraudulent identities that reach the enterprise through hiring. That same behavioral approach now extends to the hiring pipeline, catching synthetic personas and nation-state operators before access is ever granted.

Learn More About Infiltration Prevetion

Frequently Asked Questions

Isn't ATS security just our vendor's responsibility? 

Your vendor is responsible for their platform, but you're responsible for the vendor. When a misconfigured ATS exposes candidate data, your applicants are harmed and your name is on the incident. That's third-party risk, and it belongs in the process you already apply to other critical SaaS vendors.

We already scan email attachments. Isn't this covered? 

Not necessarily. Many résumés arrive through the ATS portal or a job board rather than your email, so they never pass through the controls that protect the inbox. And however a résumé arrives, a recruiter is going to open it.

Is the real risk a data breach or a fraudulent hire? 

Both, and they share the same surface. The ATS is a target for the candidate data it holds and an entry point for the people trying to get inside. This series follows the second thread: how a fraudulent identity moves from an application to provisioned access, and how to stop it.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.