For years, enterprise security teams have focused on stopping attackers from stealing employee credentials. A growing form of identity fraud presents a different problem: what happens when an attacker persuades the company to issue legitimate credentials to them?