logo

Threat Actors Taking Advantage of Open Enrollment, 401K Updates, and other Timely HR Initiatives

ID: 318e70a4-b181-5032-bf35-6aa7c90e4129

STIX ID: report--318e70a4-b181-5032-bf35-6aa7c90e4129

Feed Name: Cofense Blog

Date Published: 2024-01-10

Date Updated: 2026-04-27

Author: Cofense

...
...

This report highlights phishing campaigns that exploit end-of-year HR touchpoints—open enrollment, 401k statements, employee assessments, and salary adjustments—to harvest credentials, increasingly leveraging QR codes, ZIP-embedded HTML pages, and realistic HR spoofing. It emphasizes the effectiveness of timing and emotional triggers in social engineering and underscores the need for consistent organizational communication schedules and user education to mitigate these credential-phishing threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.