Skip to main content
Join Us at our First In-Person User Conference.Register for our Dallas event today

Sep 17, 2026

Stop Fraudulent Hires Before You Provision Access

You can't out-verify a stolen identity at the door. What you can do is make the enterprise a place where behavior that doesn't match the story surfaces early, before access is ever granted.

Key Insights

The fix is behavioral—stop asking whether an identity is real and start asking whether it behaves like who it claims to be, continuously.

Move detection earlier into the hiring funnel and keep it running after provisioning; verification at hire is only a snapshot in time.

Abnormal has flagged ~3,500 fraudulent personas in 18 months, linking actors across companies to surface them before access is granted.

A funded adversary brings a real, stolen identity and the tools to look like its owner, and your hiring controls were built to catch honest mistakes, not deliberate impersonation. It's why a clean background check is the wrong reassurance.

So change the question. Stop asking only "is this identity real?" at the door and start asking "does this identity behave like who it claims to be?", continuously, from the funnel through provisioning and beyond.

This is the same shift that reshaped the rest of security. A fraudulent hire's entire strategy is to look normal, with valid credentials and valid multi-factor authentication from day one, which means the thing that gives them away is deviation from normal. To see the deviation, you have to know what normal looks like in the first place.

This piece lays out where that detection has to happen: earlier in the funnel and continuously after the offer, the five moves that make it real, and where behavioral AI does the work a checkpoint can't. If you own security or risk and the hiring pipeline is a blind spot today, this is the part to act on.

Move Detection Earlier, and Keep It Running

Two changes matter more than any single tactic.

First, move visibility earlier up in the hiring process. Treat the hiring funnel as a monitored surface rather than a pre-security zone. The candidate is the earliest point at which you can act, and right now it's the point with the least scrutiny.

Second, keep detection running after the offer. Verification at hire is a snapshot; the fraud plays out over time. While the goal is to stop them before they enter the door, a program that stops watching once the account is live has turned off the one thing that has actually worked.

Consider the attack that happened at KnowBe4. A North Korean operative cleared four video interviews, a background check, and reference checks using a real, stolen U.S. identity, then the company-issued laptop began loading malware minutes after it powered on. No gate in the hiring process caught the operative, but what set off alerts was their behavior in the first minutes of provisioned access.  

That behavioral signal is not a one-off. Over the past 18 months, Abnormal's threat intelligence team has flagged roughly 3,500 fraudulent personas attempting to enter organizations through hiring and investigated about 1,000 more. The team has mapped a repeatable infiltration lifecycle and linked personas into networks of related actors, which is what makes early detection possible.

Five Moves to Catch a Fraudulent Identity

The playbook to stopping fraudulent hires comes down to five moves. Some of them you can take action on this quarter, while others require a longer investment. 

  1. Secure the recruiting funnel. Run a threat model on your hiring process and applicant tracking system (ATS) end to end. Decide explicitly where security gets visibility and who escalates what. The single biggest reason this attack works is that no one owns the seam between security and HR teams.

  2. Verify with signals that are hard to fake, not just documents. Favor live, interactive verification over static photo-matching, and pay attention to device provenance and how a candidate's stated location holds up. The goal is to raise the cost and complexity for the impersonator at the moments they're most exposed.

  3. Watch the first hours of provisioned access. Newly issued devices and accounts should be a period of heightened attention, not assumed trust. Unusual device setup, remote-access tooling, or activity that doesn't fit the role is exactly the tell to look for.

  4. Model identity behavior continuously across email, identity, and applications. Build an understanding of what normal looks like for each identity, then flag deviations from that specific identity's baseline. A fraudulent worker can fake a résumé and a face; it's far harder to fake the accumulated behavior of the real person they're impersonating.

  5. Build the security-to-HR escalation path before you need it. When something surfaces, the response can't wait for two teams to figure out who's in charge. Define it in advance.

Where Behavioral AI Fits

Steps three and four are where behavioral AI does the work a checkpoint can't. Abnormal AI builds a per-identity behavioral model of the people and entities an organization depends on. It learns what's normal for each one rather than matching against a list of known-bad indicators.

It's the same foundation that catches account takeover and business email compromise by noticing when an identity stops behaving like itself. It extends to the insider problem for the same reason: a fraudulent hire is, by definition, an identity that can't sustain the behavior of the person it's pretending to be.

Abnormal also sees these actors earlier because it doesn't evaluate each applicant in isolation. By linking personas across organizations through reused infrastructure, shared IP addresses, and repeated behavioral patterns, its threat intelligence connects fraudulent identities into networks of related actors. A persona that looks unremarkable to any single company surfaces as part of a known campaign.

That's the basis for Infiltration Prevention, Abnormal's approach to catching synthetic personas and fraudulent actors before they're provisioned, rather than discovering them after the damage is done. Because the behavioral model is per-identity and continuous, the same engine protecting the inbox and the identity layer is what exposes the insider who was never supposed to get in.

In-Line CTA Banner for Infiltration Prevetion

What This Means for Security and Risk Leaders

The infiltration problem is a behavioral detection problem wearing an HR costume. The controls that will actually move your risk are the ones that watch identity behavior over time, not the ones that check a document once.

Practically, that means three things. Put the hiring pipeline on your asset map and into your threat model, the same way you'd treat any externally facing system that grants access. Extend the behavioral monitoring you already trust for email and identity to the moment a new identity is provisioned, so the first hours of access are watched rather than assumed. And own the seam with HR explicitly, with a defined escalation path, so a surfaced signal turns into a decision instead of a dropped handoff.

None of this requires slowing down hiring or turning recruiters into analysts. It requires treating a fraudulent identity as what it is: an attacker who used the front door, and one your existing behavioral defenses are well positioned to catch.

See It in Your Environment

The fastest way to understand this threat is to see what it looks like in your own hiring pipeline. 

Infiltration Prevention connects to your applicant tracking system and applies Abnormal's behavioral AI to every new identity, enriching it with identity, behavioral, geolocation, and threat-intelligence signals and correlating it against known threat-actor infrastructure. When something matches, your security team gets a sourced evidence brief to review, before access is ever granted, and the hiring decision stays with the people who own it.

infiltration prevention product screenshot

Book time with our team to see the signals Infiltration Prevention surfaces, walk through real detections, and map how it fits alongside the email and identity protection you already run.

Schedule a Demo

Frequently Asked Questions

We're not a crypto or defense company. Are we really a target for fraudulent hires?

The documented victims span media, technology, finance, healthcare, manufacturing, retail, and education, including Fortune 500 companies. The scheme targets remote hiring itself, which nearly every enterprise now does, not a specific industry.

How is behavioral detection different from a better background check?

A background check is a one-time snapshot of a claim. Behavioral detection is continuous, and it watches what an identity does rather than what its paperwork says. A stolen identity can pass the snapshot; it's much harder to sustain someone else's normal behavior over time.

How is Abnormal’s Infiltration Prevention different from the insider risk tools we already have?

Most insider risk and user-behavior analytics tools start watching after someone is hired and provisioned, when they're already an authorized user inside your environment. Infiltration Prevention starts the process earlier, at the application, and correlates each new identity against fraudulent-persona activity seen across other organizations. That means a fabricated identity can be surfaced before access is ever granted, rather than investigated after it's already inside.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.