applicants whose Infosys assessments were postponed in June 2026 after proxy test-takers were found
detections a day on Seqrite-protected systems in India, Oct 2024 – Sep 2025 (265.52M in total)
of HR hiring managers plan to add screening or identity solutions within two years (First Advantage 2026)
Background check: hiring risk
Infosys postponed assessments for 20,000+ applicants after proxy test-takers were found (June 2026)
In June 2026 Infosys postponed assessments for more than 20,000 applicants after discovering that other people were sitting tests on candidates' behalf. These were human proxy test-takers. No AI impersonation was reported, and no mandatory biometric rule followed. The control that fails here is identity at the point of assessment, and it is cheap to check.
Source: Infosys / media reports, June 2026. Applicants' assessments were postponed; this was not a deferral of job offers.
Courts sentence facilitators of North Korean IT-worker schemes (Mar–Apr 2026)
US courts handed down sentences in March and April 2026 to people who helped North Korean IT workers obtain remote jobs under false identities at Western companies. The pattern, a stolen or invented identity passing a remote hiring process, is the one background verification exists to stop.
Source: US Department of Justice releases, March and April 2026.
23% of US hiring managers report losses above $50,000 a year from hiring or identity fraud
Checkr's 2025 “Hiring Hoax” survey of 3,000 US managers found that nearly one in four reported annual losses above $50,000 linked to hiring or identity fraud.
Source: Checkr, Hiring Hoax survey, 2025 (3,000 US managers). Self-reported, annual, US only.
More than one in five education checks show a discrepancy
A Veremark presentation at an HRM Asia webinar on 4 August 2026 cited education discrepancy rates of 21% and above. Inflated degrees and unrecognised institutions are the usual causes.
Source: Veremark / HRM Asia webinar, 4 Aug 2026. A vendor figure drawn from its own check volumes, not a population-wide rate.
Moonlighting is up 25–30% over three years, but remains a minority practice
Randstad India reports a 25–30% increase in moonlighting over three years. That is growth, not prevalence: other surveys put the share of employees with a second job at roughly 5–7%. The risk to employers (IP exposure, contract breach) is real but concentrated, which is why targeted UAN-based checks beat blanket suspicion.
Source: Randstad India workforce reporting.
Information security: threat watch
Condé Nast: 32.8 million records offered for sale (7 Sep 2026)
A seller advertised a 32.8-million-record dataset said to come from Condé Nast properties. The listing claims names, email addresses, physical addresses and dates of birth. It does not claim passwords or payment data. The sale offer is the seller's own claim and had not been verified at the time of writing.
Source: reporting on the 7 Sep 2026 listing. Unverified seller claim.
Bimbo Bakeries: an Oracle E-Business Suite intrusion, notified months later
Bimbo Bakeries USA was a victim of the campaign against Oracle E-Business Suite. The company determined the intrusion on 6 December 2025 and notified affected people in late August and early September 2026. ERP systems hold finance, HR and operations data and are often outside regular VAPT scope.
Source: Bimbo Bakeries breach notification, Aug–Sep 2026.
Aesto Health: 9,540,683 people reported to US regulators (1 Sep 2026)
Aesto Health appeared on the US HHS breach portal on 1 September 2026 with 9,540,683 individuals affected. It was not a ransomware case.
Source: HHS Office for Civil Rights breach portal, 1 Sep 2026.
Seqrite: 265.52 million detections in a year, about 727,000 a day
Seqrite's India threat report counts 265.52 million detections between October 2024 and September 2025, roughly 727,000 a day. Education, healthcare and manufacturing were the most targeted sectors. These are detections on Seqrite-protected endpoints, a floor and not the national total.
Source: Seqrite India Cyber Threat Report, period Oct 2024 – Sep 2025.
Kudankulam: a contractor, not the plant (July 2026)
The World Leaks group claimed an attack in July 2026 on Reliance Infrastructure, a contractor at the Kudankulam nuclear plant. NPCIL says no nuclear safety systems were affected. The lesson stands: the way in is the vendor.
Source: NPCIL statement and press reports, July 2026.
CERT-In: the 6-hour reporting rule stands, and its guidance on AI-enabled exploitation
Incidents must still be reported to CERT-In within 6 hours. CERT-In's 25 May 2026 guidance on AI-assisted exploitation points to patching on a 12-hour clock, which leaves little room for monthly patch cycles on internet-facing systems.
Source: CERT-In directions (6-hour reporting); CERT-In guidance, 25 May 2026.
The compliance clock
Background checks under the DPDP Act: what the 28 September advisory says
A 28 September 2026 advisory from law firm KS&DK sets out how the DPDP Act applies to background verification: collect only what the role needs, tell the candidate what is checked and why, and keep records of consent. The ₹250 crore penalty applies to failures of security safeguards. The consent duties themselves commence on 13 May 2027, so there is time to put a consent flow and an audit trail in place.
Source: KS&DK advisory, 28 Sep 2026; DPDP Act and Rules commencement schedule.
Our view: the process is the attack surface
Hiring and security fail in the same way: a step accepts what it is shown. This month's incidents share a pattern: Kudankulam's contractor, an ERP supplier's flaw at Bimbo Bakeries, a healthcare group's systems. The breach that hurts you may start in someone else's estate. Inventory third-party access, bring ERP and internet-facing systems into your VAPT scope, and rehearse the 6-hour reporting clock before you need it. On the hiring side, verify identity at assessment, check education and employment at source, and re-check when roles or access change.
What's new from iChek and iSec
iChek Field app for Android
Installed directly by field executives (not on Google Play). GPS check-in, time-stamped photos, works through network drops, and flags fake-GPS apps, rooted devices and emulators.
About the field app →Identity and address verification APIs, with published prices
Address and KYC APIs for real-time verification, plus video KYC with a live agent. Per-case prices and three bundles are on our pricing page.
See pricing →VulnScanAI
Nmap, OWASP ZAP and your existing VAPT tools under one platform. Every finding re-analysed by AI, PII masked automatically, agents for Windows, Linux and macOS. A free version is available to try.
Try VulnScanAI free →Sources and notes
Every figure carries the source, date or period it refers to. Unverified claims are marked as such. Published 5 October 2026.
Hiring: Infosys (media reports, June 2026); First Advantage 2026 report; US DOJ releases, Mar–Apr 2026; Checkr, Hiring Hoax, 2025; Veremark / HRM Asia webinar, 4 Aug 2026; KS&DK advisory, 28 Sep 2026; Randstad India workforce reporting.
Security: Seqrite India Cyber Threat Report, Oct 2024 – Sep 2025; Condé Nast listing, 7 Sep 2026; Bimbo Bakeries notification, Aug–Sep 2026; HHS breach portal, 1 Sep 2026; NPCIL statement, July 2026; CERT-In directions and 25 May 2026 guidance.
Get the next issue
One short, sourced brief a month on hiring fraud, background verification and information security in India.
Email us to subscribe