AI Made Fake Employees Easy to Hire, Now Companies Are Verifying Identity Before Day One

NaijaTechGuide has affiliate and sponsored partnerships and may receive a commission on featured products/services at no extra cost to you. See full Affiliate Disclosure Here

Hiring used to end with a signed offer letter and a welcome email. In 2026, it increasingly ends with a harder question: Is the new employee actually the person they claimed to be during the interview? Identity-security vendor Specops thinks that question can no longer wait until after someone already has a company account, and its newly launched product is built around answering it from the very first password.

On 13 July 2026, Specops, an Outpost24 company, launched Specops Secure Onboarding, an identity-security solution designed to verify that a new hire is genuinely who they claim to be at every stage of the onboarding journey, from setting a first Active Directory password to making a first call to the service desk.

The launch lands at a moment when artificial intelligence has made impersonation cheap, fast, and convincing enough to scale, turning what was once an administrative formality into a real security exposure.

Why onboarding became a security problem

For most organizations, onboarding was engineered for speed rather than certainty. In distributed and remote-first hiring environments, IT teams are routinely asked to provision accounts for people they have never met in person.

Temporary passwords are issued, managers hand off access, and service-desk agents reset credentials, and at nearly every step, identity is assumed rather than verified.

That gap was tolerable when impersonating an employee required real effort. It is far less tolerable now. AI-powered voice cloning, deepfake video, and automated phishing have collapsed the cost of pretending to be someone else.

A convincing fake can now be produced in minutes, which means the weakest link in the hiring process, the moment a stranger is granted trusted access, has become an attractive target.

- Advertisement -Back to School Software Deals

The numbers behind the threat

The scale of the problem is no longer theoretical. The 2026 Verizon Data Breach Investigations Report (DBIR) highlighted North Korean IT-worker schemes in which operatives used stolen identities and regionally hosted “laptop farms” to land legitimate jobs at real companies.

According to Verizon’s reporting, these operations may have leveraged as many as 15,000 stolen identities, a striking indication that fake employees are being deployed at an industrial scale rather than as one-off scams.

Separately, fraud-prevention firm Sift has reported that AI now assists more than 82 percent of phishing emails, underlining how central automation has become to modern social engineering.

Taken together, the two findings point to the same conclusion: identity risk increasingly begins at the point of hiring, before an employee’s first day, rather than weeks later, when an account is finally misused.

- Advertisement -Prepaid eSIM in over 200 Destinations

How Specops Secure Onboarding works

Specops Secure Onboarding is built to insert verification into the specific moments where identity was previously taken on trust. Rather than sending a new hire a temporary password over email or chat, the platform lets employees set their own first Active Directory password through a secure enrollment link.

Before that account is trusted, the new employee verifies their identity using biometric liveness detection checked against a government-issued ID.

Liveness detection is designed to confirm that a real, present person is completing the check, not a photo, a recorded video, or a deepfake, which is precisely the attack vector AI has made easier.

The identity check supports more than 16,000 document types across 254 countries and territories, and, notably, Specops states that no end-user data is stored during the process.

Verification does not stop at day one. Because the service desk is a frequent target for social-engineering attacks, an attacker who convinces an agent to reset a password can bypass almost every other control.

Secure Onboarding allows callers to be re-verified before sensitive service-desk actions are completed. That caller verification runs inside existing ITSM workflows such as ServiceNow and Jira, and every verification is logged for audit, giving security and compliance teams a defensible record of who was checked and when.

The aim, according to Specops, is to give IT, security, HR, and service-desk teams a single, consistent approach to identity verification that reduces onboarding risk without making the new-hire experience slow or painful.

Verification needs to start with the very first password

Specops frames the launch as a response to a shift in where identity risk actually begins.

“For years, organizations could afford to treat onboarding as an administrative process,”

said Darren James, Senior Product Manager at Specops.

“But the fake-worker schemes highlighted in the Verizon DBIR show why that assumption is becoming harder to defend. Stolen identities, remote hiring processes, and AI-enabled impersonation are changing where identity risk begins, which is why verification needs to start with the very first password and continue through high-risk support interactions.”

Why it matters beyond the enterprise

The launch reflects a broader shift in how the security industry approaches identity. The old model treated verification as something that happened once, at the perimeter, and then trusted the account indefinitely.

The fake-worker era breaks that assumption: if the person behind an account was never who they claimed to be, every downstream control inherits the lie.

That has particular relevance for regions where remote and outsourced hiring is expanding quickly, including across Nigeria and the wider African tech sector, where companies frequently onboard staff and contractors they never meet face-to-face.

In those environments, an onboarding process that verifies rather than assumes identity is not just a compliance nicety; it is a first line of defense against a category of attack that AI has made dramatically cheaper to run.

The bigger picture

Specops sits within Outpost24’s identity and access management division and, by its own account, protects more than 3,000 organizations across 65 countries, backed by native Active Directory integration and a database of more than 5.5 billion compromised passwords updated daily. Secure Onboarding extends that footprint beyond protecting existing credentials to verifying identity the moment credentials are created.

Whether identity proofing at hiring becomes standard practice will depend on how the wider market responds. But the underlying trend is hard to argue with: as AI keeps lowering the cost of impersonation, “trust, then verify” is looking less like a workable security posture and more like an open door. Increasingly, the safer default is to verify first, starting with the very first password.

Related Topics

Create YouTube Videos
Paschal Okafor
Paschal Okafor
Paschal Okafor is the founder of NaijaTechGuide. A Graduate of Electrical and Electronics Engineering, Paschal is passionate about Technology and since 2006 has written over 4000 articles covering Mobile Devices, Consumer Electronics, Digital Marketing, Mobile Apps, and Online Services. Over the past 16 years, he has managed to turn a blog that started life on a Google Blogger subdomain into the Largest Technology Blog in Nigeria and quite possibly the largest in Africa. Paschal has been Building, Analyzing, and Maintaining Websites for over 17 years and also shares his wealth of knowledge and experience about building and managing websites on NaijaTechGuide.

NaijaTechGuide Offers

Unlimited Creative Assets in One Place
Best WordPress Themes

More like this

How AI Image Generators Help Improve Content Performance Across Platforms

Content performance is no longer judged in one place. A single piece of content...

The 5 governance failures AI code governance tools are built to catch

Every AI governance conversation I join opens with frameworks. Every AI governance incident I've...

The 6 easiest Replit alternatives, ranked

Every tool in this category promises you can build an app by describing it....