
Make talent quality your leading analytic with skills-based hiring solution.

New hire onboarding fraud happens when the person who shows up to actually work the job is not the same person a company verified, interviewed, and hired. It is a distinct risk from pre hire screening fraud because it surfaces after the offer letter is signed, often on day one or weeks into the job, which means most companies have no process built to catch it at all.
Most hiring teams pour their fraud prevention budget into the front end of the funnel: resume verification, background checks, proctored assessments, video interview identity checks. All of that effort protects a single moment in time, the interview. None of it guarantees that the person who logs into the company laptop on their first day is the same human being who sat for that interview.
That gap is not theoretical. It is being actively exploited, at scale, right now.
New hire onboarding fraud is the act of substituting a different person, often called a proxy or stand in, for the individual who was actually interviewed and offered the job. The substitution typically happens at or shortly after the point where physical or remote access is granted, badge issuance, laptop shipment, VPN credential setup, not during the interview itself.
This is different from interview fraud, where a proxy sits the interview using a deepfaked or borrowed identity. Onboarding fraud is what happens next: the interview proxy hands off, or an entirely different person altogether starts logging in as the hired employee once real system access exists. Glider.ai’s writeup of a real case, candidate fraud from North Korea, documents exactly this pattern, where an individual who cleared the hiring process was later swapped out for someone else actually performing the job.
Day zero screening (resume checks, interviews, background checks) only verifies identity at a single frozen moment. Day one and beyond is when the fraud actually gets monetized, through system access, payroll, and in the worst cases, direct theft or sabotage, so skipping identity verification at onboarding leaves the highest risk moment completely unchecked.
Think of pre hire verification as checking someone’s ID at the door of a building. New hire onboarding fraud is what happens if a completely different person walks in through that same door five minutes later using the badge that was issued to whoever showed the ID. If nobody checks again once they are inside, the door check accomplished very little.
Three specific reasons this stage carries equal or greater risk than the interview stage:
Onboarding fraud typically follows one of three patterns: a proxy interviews and then hands the role to a different, less qualified individual; a single “face” is used across multiple simultaneous jobs at different companies; or an entirely different person logs in using stolen or shared credentials once equipment ships. Each pattern exploits the same weakness: nobody rechecks identity after the interview ends.
Pattern one: interview and switch. A skilled individual (or a paid stand in) passes the interview and technical assessment. Once hired, that person quietly transfers laptop access, VPN credentials, or even the physical device to someone else who performs the actual day to day work, often at a lower cost or from a different location than disclosed.
Pattern two: one identity, many jobs. The same verified identity, sometimes backed by a real but stolen document set, is used to simultaneously hold multiple full time remote jobs across different companies, an issue Dr John Sullivan and multiple identity vendors have written about as remote hiring identity fraud.
Pattern three: credential handoff post hire. The hired individual is real and did interview, but deliberately shares or sells VPN and system credentials to someone else after receiving access, converting a legitimate hire into an ongoing insider access risk.
All three patterns share a common failure point that background checks and interview verification cannot close on their own: nothing re confirms identity once the badge or the laptop actually ships.
No. Standard background checks confirm that a claimed identity has a clean or verifiable history at the time the check runs; they do not confirm that the person sitting at the keyboard on day fifty is that same person. A background check is a records lookup, not a live identity match.
This is precisely why glider.ai’s own product guidance treats identity verification and background checks as complementary layers rather than substitutes; a records check answers “does this identity check out on paper,” while a live identity check answers “is this the same physical person who was hired.” Neither layer alone covers new hire onboarding fraud end to end.
An effective day one identity check repeats the same live verification used during hiring, ideally a document plus liveness or biometric match, at the point of first system access, and then again at set intervals or trigger events afterward. The goal is a verification checkpoint, not a one time gate.
Concretely, that means:
This is the same underlying capability set that glider.ai’s ID Verify product applies during candidate screening, applied one step further down the timeline. The ID Verify product page and the recruiter’s guide to identity verification in hiring both cover the underlying document and liveness matching mechanics that make a day one recheck practical rather than a manual, ad hoc process. Teams ready to move beyond a one time check can evaluate the ID Verify homepage directly to see how a day one recheck fits into existing provisioning workflows.
Companies hiring for fully remote roles, especially in software engineering, IT support, and customer facing back office functions, carry the highest exposure, because those roles are the ones where a substituted employee can operate for months without ever appearing in person. Regulated industries, finance, healthcare, government contracting, carry an added layer of risk because a substituted employee also represents a compliance failure, not just a security one.
Smaller and mid sized companies are not exempt. Multiple 2025 reports, including coverage from TechRadar and Fortune, found dozens of Fortune 100 companies had unknowingly hired North Korean IT workers, but smaller companies with thinner HR security processes are, if anything, easier targets precisely because they lack any day one recheck at all.
New hire onboarding fraud is when the person who actually performs a job after being hired is not the same person who was interviewed, verified, and offered the role, typically discovered only after system access has already been granted.
Interview fraud happens during the hiring process itself, such as a proxy sitting an interview. Onboarding fraud happens after the offer, when the substitution occurs at the point of system access, badge issuance, or laptop delivery.
No. A background check verifies a claimed identity’s history on paper; it does not confirm that the person using company systems today is the same person who was originally hired.
Yes. Fully remote roles remove the natural in person check that a manager or office colleague would otherwise perform on someone’s first day, which is part of why remote IT and support roles are the most commonly reported targets.
A day one identity check is a live identity verification, typically a document and liveness or biometric match, performed at first login or first system access, confirming the person receiving access is the same person who was verified during hiring.
For high risk, remote, or highly privileged roles, yes. A single check at the interview stage only confirms identity at that moment; periodic or trigger based rechecks close the gap that ongoing employment otherwise leaves open.
It is related but not identical. Glider.ai’s research on how candidates cheat in hiring assessments covers manipulation during the evaluation itself; onboarding fraud is what happens after that evaluation is already passed and access is granted.
Suspend system access immediately pending verification, involve HR, legal, and security together, and preserve all identity verification records collected at hire, since those records are the fastest way to confirm or rule out a substitution.

Yes, but only partially, and usually only if you already had reasonable verification controls in place before the loss happened. There is no single retail insurance product actually called “hiring fraud insurance.” Instead, coverage for the financial fallout of a fraudulent hire is scattered across several policies many companies already own: commercial crime insurance and […]

AI proctoring does not have to feel invasive to candidates. The friction candidates report almost never comes from the security measure itself, it comes from monitoring that is unexplained, disproportionate to the role, or reviewed without a human in the loop. Done well, AI proctoring protects assessment integrity while candidates barely notice it, because they […]

AI proctoring catches more total instances of cheating across a large candidate pool because it monitors every single test taker the same way, without fatigue, distraction, or inconsistency. Human proctoring catches fewer incidents overall, but a trained human is still better at reading ambiguous, context heavy situations that automated systems can misjudge. For most hiring […]