Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Treat “fraudulent hire” as an allegation until the facts are verified. Put an incident lead in charge, promptly disable the person’s known access and revoke active sessions, preserve relevant evidence, then determine what accounts, systems, data and physical locations were reached. Coordinate the response with security or IT, HR, legal counsel and the owners of affected systems.

Start with a coordinated response

Assign one incident lead to coordinate decisions and actions across security or IT, HR, legal, leadership and system owners. The FBI recommends a concise incident-response playbook that defines responsibilities, decision authority, isolation actions, evidence preservation and law-enforcement contacts. If there is reason to think company communications may be monitored or compromised, use a channel the incident lead considers trustworthy for response coordination.

Keep a timeline of decisions and actions: who authorized them, what was changed or collected, and when. This helps teams coordinate containment and later reconcile system records with employment and equipment records.

Contain identity and system access

Disable the relevant identity-provider account and every known account assigned to the person. Revoke active sessions and tokens; a password reset alone may not end existing sessions or remove access granted elsewhere. Review administrative roles and delegated credentials, and disable VPN and remote-management access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Check the systems the person could reach, including email, SaaS applications, cloud consoles, source-code and collaboration platforms, finance or HR systems, network devices and any relevant vendor services. The NCSC/CERT insider-threat guide calls out VPN, application servers, email, network infrastructure, remote-management software, open sessions and company-issued MFA tokens in separation procedures. NIST advises immediate IT-access disablement in its discussion of employee sabotage and termination.

Look beyond the primary account

As you revoke known access, check for other paths that could remain usable:

  • Shared accounts, service credentials, API keys and OAuth grants associated with the person or their work.
  • New accounts, changed privileged groups, delegated access or vendor access created or altered during the relevant period.
  • Email forwarding rules and other mailbox changes that could continue exposing messages.
  • Administrative access to cloud services, source-code platforms, network equipment and remote-management tools.

This is an investigation checklist, not a claim that every listed artifact was used. Verify each item against the organization’s systems and logs.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Preserve evidence before it disappears

Collect relevant records promptly: log retention periods, rotation and routine cleanup can make activity harder to reconstruct. Prioritize identity and authentication events, email changes, cloud audit logs, endpoint telemetry, VPN and remote-access activity, network and DNS records, privilege changes, data exports and physical-entry records. FBI guidance recommends protected, centralized logs and synchronized clocks; CISA’s insider-threat guidance emphasizes gathering evidence across HR, cybersecurity and physical security sources.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Preserve the incident timeline and coordinate collection decisions with counsel and qualified responders when litigation or law-enforcement activity is possible. Avoid casually wiping or reimaging a device that may contain evidence. Whether and how to isolate it depends on the active risk and the organization’s response capability; coordinate the decision so containment does not unnecessarily destroy information needed to understand what happened.

Establish what the person could access and what changed

Build a time-bounded access map, starting with the hire’s account assignments and ending with the date access was contained. Include systems, data repositories, devices, physical areas and third-party services. Review the evidence for activity rather than treating access as proof that data was viewed or taken.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Evidence area What to examine Question it can help answer
Identity and authentication Sign-ins, session activity, account creation, group or privilege changes Which identities and permissions were used or changed?
Email and collaboration Mailbox rules, forwarding, access events, messages and collaboration activity Was information redirected, accessed or shared?
Cloud, applications and data Audit logs, repository and configuration changes, downloads or exports, access to sensitive records Which services or data were reached, and were changes made?
Devices, network and remote access Endpoint telemetry, VPN and remote-management events, network and DNS activity Which devices or remote paths were used, and when?
Physical security and issued assets Entry records, equipment inventories, badge and token assignments Was physical access involved, and what company property remains outstanding?

Reconcile technical records with HR records, equipment inventories, security records and witness accounts. CISA’s guidance describes collecting evidence from multiple sources and using a cross-functional threat-management approach. Record what the evidence establishes, what remains uncertain and any gaps in available logs.

Recover equipment and close physical access

Where feasible, recover company-owned computers, phones, badges, keys, smart cards, MFA tokens and other issued equipment. Disable badges and confirm the equipment inventory. Review physical-entry records and ask relevant site-security owners whether access occurred or whether other people may have used the person’s credentials or assigned assets. The NCSC/CERT guidance specifically includes closing sessions, disabling remote services and collecting company equipment, including MFA tokens.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Decide on legal, regulatory and external escalation

Involve counsel early. The applicable questions may include employment and privacy obligations, evidence handling, contracts, insurance, breach notification and whether law enforcement should be contacted. CISA advises considering law-enforcement involvement while avoiding actions that could compromise a potential prosecution. Coordinate external reporting and evidence transfers with counsel and the incident lead.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

SEC disclosure is a narrow U.S. example

For a U.S. public company subject to SEC rules, the FBI summarizes the requirement as a four-business-day Form 8-K Item 1.05 filing period after a materiality determination. Limited delay procedures are available for specified substantial national-security or public-safety risks. This deadline is not a general breach-notification rule: whether it applies depends on the organization’s SEC status and the facts, and other reporting duties depend on jurisdiction, sector, data and contracts.

What the initial response can—and cannot—establish

Official guidance supports prompt access revocation, evidence preservation, cross-functional investigation, asset recovery and deliberate legal or law-enforcement coordination. Those steps do not by themselves establish that the person committed fraud, that data was taken, or that a reportable incident occurred. Reach those conclusions from the evidence and the laws, contracts and regulatory duties that apply to the organization.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.