Hacked Before Their First Coffee: Common Onboarding Mistakes That Open the Door to Cybercriminals
- Staff Reports Human Capital Leadership Review
- 1 hour ago
- 3 min read
IMAGE: Karolis Arbaciauskas, head of product at NordPass and Nord Security.
Key insights:
The weakest link. Before their security training, new hires might not know how to spot phishing, fake login pages, or bogus IT requests — and attackers consider the first weeks of employee onboarding hunting season.
"Temporary" credentials. "Welcome2026"-style passwords, meant to be temporary, are often never changed. Unique credentials, secure delivery, forced first-login reset — that's the fix.
Beyond passwords. Excessive privileges, abandoned accounts, skipped training, and unvetted devices can also open doors for threat actors — and one wrong click can spread ransomware network-wide.
Hiring new people and onboarding them is just a part of life for growing businesses. Unfortunately, too often a new employee's first password is also a security incident waiting to happen. Weak temporary credentials, passwords sent in plain text, and sticky notes that stay on monitors forever make new joiners the easiest way for bad actors to find their way into corporate systems.
“New joiners, especially those in their first job, haven't yet developed an instinct for what looks suspicious. They might struggle to identify phishing emails, fake login pages, bogus password reset requests, fake IT help desk messages, and malicious attachments disguised as onboarding documents. The first few weeks, before cybersecurity training kicks in, are the most dangerous because newcomers are more likely to make mistakes and follow instructions without asking too many questions,” says Karolis Arbaciauskas, head of product at cybersecurity company NordPass and its parent organization Nord Security.
“Temporary” passwords
Arbaciauskas points out that the problem often starts even before day one — sign-in credentials are often sent via email, messaging app, or SMS in plain text. People do not always delete those messages, so the information stays there unencrypted and can be intercepted or stolen.
Handing out laptops with passwords on sticky notes attached is just as bad an idea because those sticky notes will likely stay on employees' desks forever, tacked to the monitor or a partition.
“It’s also common to try to make onboarding user friendly for new hires before they arrive by setting up temporary credentials. Those first-day credentials are often simple and created using a company name, new employee name, or an easy-to-remember phrase, like “Welcome2026,” because they're meant to be changed. Unfortunately, those temporary credentials often become permanent and get reused across accounts. It's best to generate unique credentials, deliver them through a secure channel, such as a password manager, and force a reset on first login,” says Arbaciauskas.
Other common onboarding mistakes that increase cybersecurity risk include:
Excessive access privileges. Giving new hires full administrative or wide network access instead of following the principle of least privilege.
Abandoned accounts. Failing to revoke access promptly when a new hire changes roles or leaves shortly after starting — for example, after not passing the probationary period.
Delayed security training. Postponing foundational phishing and cyber hygiene training until weeks after the employee's start date — or skipping security awareness training entirely.
Missing security policies. Leaving new employees without clear guidelines on acceptable use of digital tools, data handling, and reporting suspicious activity.
Unvetted devices. Allowing personal devices to connect to corporate networks without endpoint security or mobile device management (MDM).
These oversights create immediate security gaps, exposing organizational networks to insider threats and data breaches. Conducting a proper and secure onboarding should not be optional. A single wrong click can be enough to spread ransomware throughout the entire network or give attackers access to critical systems.
NordPass is a password manager for both business and consumer clients. It's powered by the latest technology for the utmost security. Developed with affordability, simplicity, and ease of use in mind, NordPass allows users to access passwords securely on desktops, mobile devices, and browsers. All passwords are encrypted on the device, so only the user can access them. NordPass was created by the experts behind NordVPN — the advanced security and privacy app. For more information: nordpass.com.






















