logo

Fake 401K year-end statements used to steal corporate credentials

ID: bc46a887-316f-583d-9bad-fbbb7b4c3226

STIX ID: report--bc46a887-316f-583d-9bad-fbbb7b4c3226

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2024-01-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cofense reports a rise in targeted phishing campaigns that impersonate HR-related communications (401(k) notices, open enrollment, pay raises, and performance reports) to steal employee credentials; attackers increasingly embed QR codes linking to fraudulent login pages, and defenders are advised to schedule legitimate HR communications, educate staff, and avoid using QR codes in sensitive corporate messages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.