HR News | Employer's Guardian

New-Hire Fraud: What Employers Need to Know

Written by Admin | Aug 18, 2026, 3:39:05 PM

New-hire fraud covers two distinct problems that share a moment in the employment lifecycle: schemes that target new employees because they do not yet know what normal looks like, and schemes in which the new hire is the fraud — a fabricated or misrepresented identity placed onto payroll.

Both concentrate in the first weeks of employment, and both are addressed at onboarding or not at all.

New hires as targets

A person in their first week is unusually vulnerable to social engineering, for reasons that have nothing to do with judgment. They have not met most colleagues and cannot recognize an impersonation. They do not know which requests are routine. They are motivated to be responsive and agreeable. And they are receiving so much unfamiliar information that one more odd request does not stand out.

Attackers exploit this directly. The common patterns are a message purporting to come from an executive asking the new employee to handle something urgent, a request to confirm banking details framed as payroll setup, and a fake IT contact asking them to verify credentials as part of account provisioning.

Public announcements make targeting straightforward. A welcome post naming a new hire and their role provides everything an attacker needs, and the timing is precise.

The countermeasure is a conversation in week one telling the new employee explicitly what the organization will never ask them to do, that no legitimate urgent request will bypass their manager, and exactly who to contact when something feels wrong. It takes about five minutes and is among the highest-return interventions in onboarding.

The fraudulent hire

The second category is a person entering employment under a false or misappropriated identity. This ranges from an applicant using someone else's identity documents to a fully fabricated identity constructed to obtain wages, benefits, or access.

Remote hiring has made this materially easier, since document review conducted over video removes physical inspection, and an employee may never meet a colleague in person. A related pattern involves someone other than the interviewed candidate performing the job after hire.

The consequences are not limited to wages paid to a nonexistent worker. A fraudulent hire may obtain system access, and where the identity was stolen from a real person, that person is harmed by employment records and tax filings created in their name.

Verification within the rules

The controls here have to operate inside anti-discrimination constraints, which is why employers acting from caution frequently create their own exposure.

Employment eligibility verification requires examining documents the employee chooses to present from the acceptable lists. The employer may not specify which documents it wants, may not demand additional or different documents, and may not reject documents that reasonably appear genuine. Applying extra scrutiny to employees who appear foreign-born or who mention a non-citizen status is unlawful document abuse, regardless of intent.

The workable position is uniform process rigor rather than selective suspicion: the same verification steps for every hire, applied consistently, documented identically. Consistency is both the legal requirement and the more effective control, since fraud detection built on impressions about who looks suspicious performs poorly.

Payroll-side indicators

Several signals are visible in payroll data and worth building into routine review:

  • A new payroll record with no corresponding onboarding file — the classic ghost employee signature
  • Multiple employees sharing a bank account
  • Multiple employees sharing an address or phone number, beyond what family relationships explain
  • A banking detail change requested within days of the first paycheck
  • An employee who never appears for anything requiring physical presence
  • Onboarding paperwork completed unusually quickly with minimal supporting detail

The first is the most important and requires the least sophistication to check: reconciling payroll additions against actual hires each cycle. A ghost employee shifts totals by one salary, which is usually within normal variance and therefore invisible without a line-level comparison.

Sequencing access

Access is often granted before onboarding paperwork is complete, sometimes before employment is finalized, because the priority is getting the person productive. Sequencing access to follow completed documentation and identity verification closes a window that costs nothing to close.

It also means that where a fraudulent hire is identified during onboarding, they have not already accumulated system access that then needs unwinding.

Internal collusion

The most costly variant involves someone inside the organization — a manager creating a fictitious employee, or a payroll administrator adding a record. This defeats process controls because the person operates within them.

Separation of duties is the answer: the person who initiates a hire should not be the person who adds them to payroll, and reconciliation of payroll additions against HR records should be performed by someone independent of both. Where one person can complete the entire sequence, no workflow provides protection.

Employer's Guardian helps employers structure onboarding verification, documentation, and the consistency these controls depend on through onboarding documentation compliance.

This article provides general educational information, not legal advice. Verification requirements are subject to anti-discrimination rules. Consult qualified counsel before changing hiring or verification practices.