HR and Payroll Phishing
Salary reviews, payslips, bonuses, policy updates and benefits enrolment are powerful phishing lures. How HR and payroll phishing works and how to check HR messages safely.

"Your salary review is ready." "Updated payslip attached." "Complete your benefits enrolment by Friday." HR and payroll emails get opened, because they concern your money and your job. That is exactly why phishers imitate them.
Common HR and payroll lures
- Salary adjustment or bonus letters.
- Payslips or tax forms "attached" or "available".
- Policy updates you must "acknowledge".
- Benefits enrolment deadlines.
- Performance review invitations.
- Holiday or leave balance notices.
hxxps://hr-portal-docs[.]comPayroll diversion
Attackers also target HR staff directly, emailing as an employee: "I have changed banks, please update my salary account." If HR updates the details without checking, the next salary goes to the attacker. See phishing aimed at HR.
How to stay safe
- Open HR and payroll systems through your usual bookmark or intranet.
- Be suspicious of HR emails with external links or unusual attachments.
- HR teams: confirm bank detail changes with the employee in person or by a known phone number.
- Report suspicious HR emails, especially at review and bonus time.
Got an HR email you are unsure about? Paste it into CyberWatch AI Scan for a free check.
For more, see how to recognise phishing in our complete guide.
Frequently asked questions
Why are HR emails used for phishing?
Because they involve money, jobs and personal matters, which people open quickly and without suspicion.
How do I check an HR email?
Go to your HR or payroll system through the usual bookmark or intranet, or contact HR directly. Do not use the link.
What is payroll diversion?
When attackers change an employee's bank details in the payroll system, often after phishing their login or impersonating them to HR, so salary goes to the attacker.
Sources
- Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency
- Suspicious email actions, UK National Cyber Security Centre
- Cybersecurity for Small Business, US Federal Trade Commission


