Fake HR benefits enrolment scams work because they arrive when employees expect a genuine annual reminder, payroll update or workplace-benefits change. A message that appears to come from HR can send a staff member to a fake portal asking for identity details, banking information or a work password. This 2026 guide gives HR and security leaders a practical training plan for verifying benefits messages and reporting suspicious requests.
TL;DR
- Treat an unexpected benefits enrolment message as an untrusted request until HR confirms it.
- Open the benefits or payroll portal from a saved bookmark or approved employee hub, not from an email link.
- Check the sender, destination, request and timing before entering information.
- Use a second channel to confirm changes to bank details, superannuation, tax information or emergency contacts.
- Practise the behaviour with security awareness training, then measure reports, clicks and time to escalation.
Why fake benefits messages work
Benefits communication is personal, time-sensitive and often unfamiliar. Employees may visit the benefits portal only once or twice a year, so they may not remember the normal login route. A message about open enrolment, a new wellbeing benefit, salary packaging or a payroll correction can look legitimate simply because it matches the calendar.
The request may arrive by email, text message or collaboration chat. It may use a real HR team member’s name, copy the organisation’s logo and include a deadline. The destination may ask for a work password, date of birth, tax-file details, bank information or an MFA code. Those details can support identity fraud, account takeover or payment diversion.
The answer is not to make employees distrust HR. Give them a clear process that is easier than following the message. Employees should know where genuine announcements appear, who can confirm them and what HR will never request by email.
What the training needs
- The approved employee hub, payroll system and benefits portal.
- A saved official login route for each service.
- HR and payroll contacts who can confirm unusual requests.
- A rule that bank, superannuation and tax changes require independent verification.
- MFA for HR, payroll and benefits administrators, with recovery details owned by named people.
- A reporting route that accepts the original message without asking staff to resend passwords or personal information.
The steps
1. Define the genuine enrolment process
Document how a legitimate benefits campaign is announced, where the information is published and how employees enrol. State the normal sender address, employee-hub location, portal name and deadlines. Explain whether HR sends direct links or whether every message directs employees to the internal hub.
List what HR may request through the approved system and what it will never request in an email reply. Include bank-account changes, superannuation choices, tax details, identity documents and MFA codes. The clearer the boundary, the easier it is for an employee to stop a suspicious request.
Expected outcome: a new employee can find the official benefits portal without opening an email link. Common mistake: telling staff to “watch for scams” while leaving the real enrolment path hard to find.
2. Teach four checks before entering information
Give employees a routine that works during an enrolment deadline. First, expand the complete sender address and compare it with the known HR domain; a familiar display name is not proof of identity. Second, do not use the message link: open the saved employee hub or approved portal directly. Third, ask whether the message requests information HR normally collects through that system and whether it asks for a password, code or secrecy. Fourth, treat a surprise deadline, threat of losing a benefit or pressure outside normal hours as a reason to verify.
Do not rely on spelling, logos or a padlock. A well-designed fake page can still be controlled by an attacker. The safe decision is to use a known route, not to become an expert at judging visual details.
Expected outcome: staff can pause an unexpected benefits message in under a minute and reach the correct portal without following the lure.
3. Separate announcements from high-impact changes
A genuine announcement is different from a request that changes money or identity information. Require an additional check for bank details, superannuation, salary packaging, tax information, emergency contacts and dependent records.
Use a known HR or payroll contact from the employee directory. Do not reply to the suspicious email or call a number inside it. HR should confirm whether the request is real and tell the employee how to complete it through the official system.
Use a two-person approval rule for administrator changes and payroll configuration. A single email should never be able to create an administrator, alter payment details and provide the only verification route.
Expected outcome: a stolen password or convincing impersonation cannot immediately change a person’s pay or benefits. Common mistake: treating a familiar HR name as enough evidence for a sensitive change.
4. Make MFA part of the lesson
MFA helps protect an account, but it does not make an unexpected prompt safe. Teach staff to reject a sign-in or approval they did not initiate, never read a one-time code to someone on a call and never enter a code into a page opened from a benefits message.
Show HR and payroll administrators where to review active sessions, recovery addresses, new devices and connected applications. Keep recovery information current when staff move roles or leave. Include contractors and outsourced payroll providers in the access review.
Expected outcome: employees know that an unexpected MFA prompt is a reportable event, not an instruction to keep approving until the portal works.
5. Run a safe, role-specific simulation
Use a fictional scenario that resembles the organisation’s calendar: an open-enrolment reminder, new wellbeing benefit, payroll correction or request to confirm dependants. The exercise should use a harmless landing page that collects no passwords or personal information and explains the warning signs immediately after the decision.
Measure delivery, clicks, reports, time to first report and whether the employee used the official route. Review HR, finance, managers and general staff separately because the message that persuades one group may not persuade another.
Run the first exercise within 30 days of the lesson and vary the scenario later in 2026. A repeated template tests memory; varied scenarios test behaviour. Keep coaching private and focus on the process that would have prevented the click. Use phishing simulations to reinforce the habit.
6. Practise the response after exposure
If an employee entered a password, personal detail, bank information or MFA code into a suspected fake portal, the first action is to stop and report. Do not revisit the page, delete the message or feel responsible for proving the scam before escalating.
The account owner should secure the email account if it controls recovery, reset the exposed password from a clean device, revoke active sessions and review new devices and connected applications. HR or payroll should check for changes to bank details, dependants, tax information, benefits selections and administrator access. If financial information was exposed, involve the response owner immediately.
Preserve the message, destination, time and action taken. A calm reporting culture helps HR distinguish a suspicious message from a confirmed account change without discouraging the next report.
Expected outcome: HR hears about a suspected exposure before the next payroll or enrolment deadline. Common mistake: waiting for a missing payment or visible account takeover.
7. Measure and refresh the programme
Track completion, click rate, report rate, median time to report, unexpected MFA approvals and repeated misses. Compare like-for-like scenarios and keep the denominator visible. Review results by employment type, location and access level where privacy and fairness allow.
Use human risk reporting to bring learning completion, simulation outcomes and follow-up tasks into one view. Treat results as a way to improve the process, not as a permanent label on an individual.
Refresh the lesson when the organisation changes its payroll provider, benefits platform, HR contact process or employee hub. New starters should learn the official route before they receive an enrolment deadline.
Troubleshooting
Employees cannot tell whether a message came from HR. Stop asking them to decide from appearance. Publish the normal process in the employee hub and require staff to start there.
A benefits provider sends a direct link. Confirm the provider and link through the recorded HR contact before using it. Add verified provider details to the employee hub for future campaigns.
The message says a benefit will disappear today. Treat urgency as a reason to verify, not a reason to skip the process. HR should make the genuine deadline visible through a trusted channel.
An employee entered bank details. Stop, report, preserve the message and notify HR, payroll and the relevant response owner. Review whether a payment or profile change was made and use the financial institution’s official route if required.
The team reports too many legitimate messages. Include real examples in the next lesson and show the official portal route. The goal is confident verification, not suspicion of every HR announcement.
A practical 30-day rollout
In week one, document the genuine enrolment process, official portal and sensitive-change rules. In week two, deliver a short lesson and ask staff to find the portal without a message link. In week three, run a safe simulation. In week four, review reports, response time and any part of the process that caused confusion.
Use a cyber security gap assessment to record missing owners, stale access, weak recovery steps and unclear payroll approvals. If the organisation is comparing providers, use compare security awareness platforms after defining the reporting and role-based learning requirements.
FAQ
How can staff spot a fake HR benefits message?
Check the sender, avoid the message link, open the saved employee hub and verify sensitive requests through a known HR or payroll contact. A familiar logo or deadline is not enough.
Should HR email employees a direct login link?
The safest default is to direct staff to the approved employee hub or saved portal route. If HR uses direct links, the process should be documented and the destination independently verified.
What information should HR never request by email?
Passwords, one-time codes and MFA approvals should never be requested in an email reply. Sensitive bank, tax, superannuation and identity changes should use the approved system and verification process.
What should happen after an employee enters details into a fake portal?
Stop, report, preserve the message and secure the affected account. Reset exposed credentials from a clean device, revoke sessions and check for changes to payroll, benefits and administrator access.
How often should benefits phishing training run in 2026?
Run an initial lesson, a safe simulation within 30 days and a varied refresher when enrolment opens or the HR and payroll process changes. New starters should receive the route before their first deadline.
What should HR measure?
Track completion, click rate, report rate, time to first report, unexpected MFA approvals and whether staff used the official portal. Compare similar scenarios by cohort.
One last thing
Employees should never have to decide whether a benefits message looks real before they can act safely. Give them a known portal, a named HR contact and a second check for money or identity changes. That process turns a convincing enrolment lure into a report instead of a payroll incident.