Blog/Phishing

HR and Payroll Phishing

Salary reviews, payslips, bonuses, policy updates and benefits enrolment are powerful phishing lures. How HR and payroll phishing works and how to check HR messages safely.

CyberWatch AI1 October 2026 · 2 min read
Two people writing on documents at a desk

"Your salary review is ready." "Updated payslip attached." "Complete your benefits enrolment by Friday." HR and payroll emails get opened, because they concern your money and your job. That is exactly why phishers imitate them.

Common HR and payroll lures

  • Salary adjustment or bonus letters.
  • Payslips or tax forms "attached" or "available".
  • Policy updates you must "acknowledge".
  • Benefits enrolment deadlines.
  • Performance review invitations.
  • Holiday or leave balance notices.
Illustrative example · Email
From: Human Resources Subject: Confidential: 2026 Compensation Update Your revised compensation letter is available. Sign in with your work account to view and acknowledge it by end of day: hxxps://hr-portal-docs[.]com
Red flags: curiosity about pay, a deadline, and a login page outside your company's usual HR system.

Payroll diversion

Attackers also target HR staff directly, emailing as an employee: "I have changed banks, please update my salary account." If HR updates the details without checking, the next salary goes to the attacker. See phishing aimed at HR.

How to stay safe

  • Open HR and payroll systems through your usual bookmark or intranet.
  • Be suspicious of HR emails with external links or unusual attachments.
  • HR teams: confirm bank detail changes with the employee in person or by a known phone number.
  • Report suspicious HR emails, especially at review and bonus time.

Got an HR email you are unsure about? Paste it into CyberWatch AI Scan for a free check.

For more, see how to recognise phishing in our complete guide.

Frequently asked questions

Why are HR emails used for phishing?

Because they involve money, jobs and personal matters, which people open quickly and without suspicion.

How do I check an HR email?

Go to your HR or payroll system through the usual bookmark or intranet, or contact HR directly. Do not use the link.

What is payroll diversion?

When attackers change an employee's bank details in the payroll system, often after phishing their login or impersonating them to HR, so salary goes to the attacker.

Sources

  1. Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency
  2. Suspicious email actions, UK National Cyber Security Centre
  3. Cybersecurity for Small Business, US Federal Trade Commission
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.