Open Enrollment Phishing Turns HR's Busiest Season Into Cover
Benefits season is the one time a year HR asks every employee to click, sign in, and update their details — which is exactly why impostors time their messages to it.
Every fall, HR does something it spends the rest of the year telling employees never to trust: it sends a wave of emails and texts asking people to click a link, sign in, confirm their dependents, review their deductions, and act before a deadline. Open enrollment phishing works because it doesn't need to invent a pretext. Your benefits calendar already supplies one, on a schedule anyone can guess, to a workforce that has been told to expect exactly these messages. For a company of a few hundred people, that means a few hundred inboxes primed to comply.
Why open enrollment phishing lands at companies your size
At a ten-person shop, everyone knows the one person who handles benefits and would walk over to ask. Somewhere past fifty employees that stops being true. Messages start arriving from a benefits administrator, a broker, a payroll platform, a carrier, a new HRIS, and two or three people in HR whose names half the staff wouldn't recognize. Each sender is legitimate. Together they teach employees that benefits email comes from many places, looks a little different each time, and usually asks for a login.
Impostors do not need to breach anything to exploit that. Enrollment windows fall in the same weeks every year, and org charts are easy to reconstruct from professional networking sites. A message that says "Your 2027 elections are incomplete — confirm by Friday to avoid losing coverage" is plausible on its face at almost any company in October.
Payroll diversion rides the same wave
The phishing email is usually step one. What attackers want is either an employee's HR or payroll login, or a request that gets someone in HR to change where a paycheck goes. The FBI has warned about payroll diversion for years, and the pattern is simple: an email that appears to come from an employee asks payroll to update their direct deposit, timed so the next pay run lands in a new account before anyone notices.
Enrollment season makes both directions worse. Employees are updating personal details anyway, so a deposit change doesn't look unusual, and HR is processing a spike of legitimate changes under its own deadline pressure.
Polish stopped being a signal
Security training long leaned on surface tells: odd greetings, clumsy phrasing, a logo slightly off. Those were never reliable, and generative tools have removed most of them. A fraudulent enrollment reminder can now read exactly like your broker's, reference your actual plan names, and arrive in clean, confident prose.
Be precise about what that changes. The issue isn't that fraudulent messages are machine-written. Plenty of legitimate HR email is drafted with software help. The issue is that fluency no longer tells anyone anything about who sent a message. Neither employees nor payroll staff can sort real from fake by reading more carefully. The check has to live somewhere other than the words.
Give both directions a verifiable sender
For HR operations and the IT or security team working alongside it, the useful reframe is that this is an identity problem running in two directions.
Outbound, employees need a fast way to confirm that a benefits message came from someone actually authorized to send it. That means a named person whose identity an employee can look up in seconds, not a shared inbox with a friendly display name.
Inbound, payroll needs a way to confirm that a change request was authorized by the employee it names, beyond "the email came from their address." A request tied to a verified identity, or a short verification code the employee generates for that specific change, gives payroll something to check other than tone.
This is the layer HumanVerified for organizations is built around. People in HR and benefits roles each get a Human ID that employees can look up. Messages that matter can carry a verification code tied to the person who authorized them. Administrators can issue and revoke those identities as people join, change roles, or leave, so the list of people who can be confirmed matches the people actually doing the work. An HR coordinator who left in June should not still be a credible sender in October.
What verification covers, and what it doesn't
Overpromising here would undercut the point. HumanVerified confirms that a communication was personally reviewed and authorized by the person shown. It doesn't certify that the plan details, deduction amounts, or deposit instructions inside are correct. It doesn't claim the message was written without the help of artificial intelligence, and it doesn't try to detect whether it was. The verification policy is deliberately narrow for that reason.
What it does is close off a whole category of approach. Anyone can write a convincing enrollment reminder. They can't produce an active identity your company issued and hasn't revoked, and an employee who has been told plainly how to check will notice when one is missing.
Where HR operations can start before the window opens
None of this requires rebuilding your benefits stack. It comes down to a few habits, best set before enrollment opens rather than during it.
Name the senders. In the kickoff announcement employees actually read, say exactly which people and platforms will contact them about benefits this year, and how to confirm each one. Put payroll changes behind a second check: treat any direct deposit change that arrives by email as unconfirmed until it is verified through a channel the requester didn't choose, such as a verification code, a known phone number, or the employee making the change inside the payroll system. And keep the sender list current, issuing verifiable identities to everyone in HR, benefits, and payroll roles who contacts employees, and revoking them with the same discipline you apply to system access.
AI can help write the message. What employees and payroll staff need to know this fall is who is willing to stand behind it.
Verify your team's communications
Give every person on your team a verifiable identity your clients can check in seconds. Free during beta.
Request organization access