The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
Summary
Organizations are vulnerable to security threats from fake remote workers who exploit gaps in the hiring process, such as between background checks, device delivery, and account activation. Specops Software suggests implementing document verification and biometric liveness checks to ensure the legitimate new hire is the one gaining access.
IFF Assessment
The article highlights a method for threat actors to infiltrate organizations by impersonating new hires, posing a direct risk to defenders.
Defender Context
Defenders need to be aware of social engineering tactics that target the onboarding process. Implementing robust identity verification procedures, including biometric checks and thorough background investigations that extend to device delivery and account provisioning, is crucial to prevent unauthorized access.