The full research report is live.
I just wrapped up a long stretch of research on the candidate fraud landscape. Sixty-plus vendors, nine product categories, interviews with practitioners at companies of every size and product leaders from the vendors trying to solve this.
Going in, I expected the most interesting findings to be about the products. Whose detection actually works, which architecture wins, where the false positive rates land. That stuff is in the report.
But the biggest finding came up in almost every conversation, at every company size: the same chair is empty in the same room. The CISO isn't there. And nearly every other problem in this market (slow buying cycles, half-deployed tools, budgets that don't add up, response protocols that don't exist) flows from that one fact.
Candidate fraud is a security problem that nobody formally owns. And the place that gets resolved is the CISO's office.
This stopped being an HR problem in 2024
For most of its history, candidate fraud was a quality-of-hire problem. Padded resumes, inflated titles, a friend posing as a reference. Annoying, sometimes costly, but bounded by the damage a bad hire could do in a few months. It lived in HR because the worst case scenario lived in HR.
That problem still exists. It's just not the one that matters now.
In July 2024, KnowBe4, a security awareness training company whose entire business is teaching people to spot deception, hired a Principal Software Engineer who turned out to be a North Korean operative using a stolen American identity. He passed four video interviews, a background check, and reference verification. He only got caught because the company's own endpoint software flagged his workstation loading malware within minutes of his start date. The CEO's post-mortem included a line most companies would never publish: "Do we have egg on our face? Yes."
The N. Korean IT worker scheme goes back to 2018. The first major US government warning landed in 2022. CrowdStrike documented a 220% year-over-year jump in identified incidents over the last twelve months.
Think about the MGM breach. It started with a ten-minute phone call to an IT help desk and ended in roughly $100 million in damages. Candidate fraud is that same threat moved one step earlier. If an attacker can impersonate an employee to get access, they can impersonate a candidate to get hired, and walk in with a laptop, credentials, and access.
If that's not a security problem, then I genuinely don't know what is.
Sources: CrowdStrike, public breach reporting, KnowBe4
And the defenses thin out exactly where the stakes rise. Across the hiring funnel, coverage clusters at the top, where fraud is cheap to catch, and all but disappears at the bottom, where a fraudulent hire is already inside.
Defenses cluster where fraud is easy to catch
Relative vendor coverage by funnel stage. The highest-consequence stage, post-hire, is the least defended.
So why isn't the CISO all over this?
I kept asking, and I kept hearing three answers. Hiring sits outside the traditional security perimeter. There's no playbook. And the legal exposure around employment decisions makes security teams nervous.
All three are real. None of them hold up.
The perimeter argument was true in 2018. Not anymore. The KnowBe4 operative was inside the network within 25 minutes of his start date. A Nisos investigation uncovered a 40-device laptop farm in Florida running coordinated identities at multiple US companies at once. The whole point of the DPRK model is that the attack starts once the offer letter is signed. The hiring funnel is now the first step of the network attack. Any CISO still drawing the perimeter at the firewall is defending something that stopped existing two years ago.
The playbook argument is more honest, but it's self-fulfilling. There's no playbook because CISOs haven't written one. Many of these vendors are months old, or at least the products they're bringing to market are. The institutional knowledge for investigating and escalating a flagged candidate lives in a handful of people's personal notes. If you're waiting for the playbook before you engage, you're waiting for someone with less authority than you to write it for you.
The legal argument is the strongest of the three. Automated decision-making in employment is a live regulatory area, and getting it wrong on the discrimination axis costs more than getting it wrong on the fraud axis. Fair.
But the exposure exists whether or not the CISO is in the room. The choice isn't "engage and take on risk" versus "stay out and stay clean." It's "engage and shape the policy" versus "stay out and inherit a policy someone else writes in a panic after the incident." The second one is worse.
The gap looks the same at every company size
My starting assumption was that this was a small-company problem. No security team to spare, so the work falls on the TA leader by default. But surely large enterprises are on the offensive.
The research didn't support that at all.
On one end, I talked to a TA leader at a mid-sized security company - a few hundred people. A recruiting team of two, reporting into a CFO. He'd personally demoed Greenhouse's fraud product. He'd researched building his own detection workflow with Claude Code and Zapier, modeled on another head of talent who'd done exactly that. His take: the business could treat this as its problem, but it doesn't, so he does. Out of conscientiousness, not mandate.
On the other end, I talked to a TA leader at one of the largest, best-resourced tech companies in the world. Their security org is one of the most sophisticated anywhere. They've known about candidate fraud for well over a year. But the gap is still there. They chose to handle it mainly through recruiter enablement rather than tooling, partly because detection error rates were too high to act on confidently. HR and IT rarely collaborate on it, and there's no urgent push to buy.
That second example is the most surprising and concerning. If this were a resourcing problem, the most security-mature enterprises would have solved it already, getting ahead of the inevitable. They haven't. The gap isn't budget or headcount. It's structural. Candidate fraud has no natural home on the org chart, and more org chart doesn't create that home that is so clearly needed.
The single best diagnostic question
If I could give a CHRO or CEO one question to assess their candidate fraud posture, it's this, and it came up unprompted from both vendors and practitioners:
Is your CISO actually involved?
That singular question tells you three things. Whether the org has classified this as a security problem instead of an HR inconvenience. Whether there's real budget, sized for a security threat instead of scraped off the margins of a recruiting P&L. And whether anyone has the mandate to set policy and escalate, which a TA team alone doesn't.
The practitioner with the two-person team got there on his own. If he ever found a tool that truly solved his problem, he told me, the only way to fund it would be to capture budget from the executive who owns security risk. He'd found the unlock. He just wasn't the one who could pull it.
Vendors said the same thing from the other side of the table. The strongest signal that a deal is real, with likelihood to close, is whether security is in the room.
The problematic corollary: where the CISO isn't involved, what you actually have is a motivated TA leader doing their best inside a bubble, for the good of the company. That describes most of the TA leaders I spoke with.
What working ownership actually looks like
The companies doing this well didn't find the perfect tool. They found an ownership structure. Four models surfaced throughout my research.
Model 01
A published framework
A written protocol for what happens when a candidate gets flagged. Who reviews, who decides, who escalates. Quora's is the most-cited example. The content matters less than the fact that it's written down and agreed on.
Model 02
A post-incident rebuild
KnowBe4 is the canonical case. An actual incident forces the org to resolve ownership. Reactive, but durable.
Model 03
A cross-functional committee, pointed the right direction
The most interesting pattern in the whole research. One large enterprise has a dedicated security manager sitting inside the HR org, formally coordinating across as many as eight functions. Instead of TA reaching outward for a security partner who may never engage, the company assigned security inward, into HR. That one structural decision did most of the work.
Model 04
A single named owner
Fragile, because it depends on one person. Still vastly better than nobody.
The common thread: TA is involved in every working model, but TA never carries it alone.
Where this goes
Two paths from here. In one, candidate fraud gets absorbed into the security org and becomes another threat category the CISO owns, with TA as input. That's the cleanest outcome and probably the most likely one, because it requires no new invention. Just the CISO claiming ground they should already be on.
In the other, a new function emerges at the intersection, the way Trust & Safety emerged a decade ago once platforms realized content moderation belonged neither fully to engineering nor fully to policy. I heard "TA security analyst" floated in more than one conversation I had. It doesn't exist yet. It probably should.
Either way, here's where most companies are today: the honest answer to "who owns this?" is a motivated TA leader, not a structure. The technology is moving faster than the org chart. And the technology doesn't help you when a flag fires and nobody in the building has the mandate or know-how to act on it.
The most consequential candidate fraud decision your company makes in the next two years isn't which vendor to buy. It's whether the CISO walks into the room.
Right now, that chair is still largely empty.
Read the full research, or bring your questions live.
