• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
NewslettersFortune CHRO

The most-clicked phishing emails pretend to come from HR—and their subject matter might surprise you

By
Paige McGlauflin
Paige McGlauflin
and
Joey Abrams
Joey Abrams
Down Arrow Button Icon
By
Paige McGlauflin
Paige McGlauflin
and
Joey Abrams
Joey Abrams
Down Arrow Button Icon
August 2, 2023, 8:23 AM ET
Shot of a hacker dressed in a black mask hacking a computer.
Employees are falling for HR-related phishing scams.PeopleImages—Getty Images

Good morning!

Recommended Video

Your organization’s next cybersecurity nightmare may come from scammers masquerading as HR. According to security software company KnowBe4’s second-quarter 2023 global phishing report, half of the top phishing tests employees clicked featured HR-related subject lines.

Per the study, fake HR email subjects included information related to vacation (19% of all successful phishing email tests), dress code policies (11%), requests for W-4 updates (11%), and training deadlines (9%). Non-HR-related email scams that received high clicks cited potential typos, Adobe “requests” to sign off on performance reviews, and fake Google notifications about mentions in a shared document.

“We saw a huge uptick in the HR emails getting used,” says James McQuiggan, a security awareness advocate at KnowBe4. “Anything that’s authoritative, anything that drives that emotion with users, [employees will] be real gung ho trying to find out what’s going on.”

Phishing scams create a sense of urgency for the victim, prompting them to click the bait without caution. Although many employees have learned to catch more obvious scams, like fake invoices or requests from an attacker impersonating the CEO, it’s easier to let one’s guard down when the email subject concerns payroll or vacation policy changes.

“Creating that sense of urgency is really part of the toolkit that an attacker would use, and if you’re like me or other employees, you’d be concerned if you had an email from HR in general,” says Deron Grzetich, national cyber leader at West Monroe, a digital services firm headquartered in Chicago.

Employers and HR teams can practice three actions to prevent phishing scams.

1. Invest in security tools like two-factor authentication or email filtering software to help prevent phishing scams from landing in inboxes.

2. Make employees aware of cyber risks and how to report them. Establish communication best practices with employees.

3. Announce policy changes or updates in another forum besides email, such as a Slack channel or internal portal to update staff or tasking managers with sharing new HR guidelines.

CHROs should also provide employees with step-by-step instructions for accessing such information internally without clicking on a URL in an email. “Communication is key when you’re making changes like that. If there are other out-of-band communication methods that you can do with your users, then that goes a long way as well, rather than just relying on [saying], ‘Hey, there’s this email coming,’” says McQuiggan.

Think of it as operating like a bank would with client communications, Grzetich says. “​​My bank wouldn’t give me an emailed link to click on. They would tell me to go to the bank website and log in. HR could do that as well.”

Paige McGlauflin
paige.mcglauflin@fortune.com
@paidion

Reporter's Notebook

The most compelling data, quotes, and insights from the field.

By 2040, employers could help Americans expand their life span by 12 years and their years spent in good health by 19, according to a new report from Deloitte.

Company-provided health insurance covered more than half of U.S. residents in 2021. Offering benefits that support workers’ physical and emotional well-being could boost productivity and retention and reduce health care costs through illness prevention, the report finds.

Around the Table

A round-up of the most important HR headlines.

- Around 84% of LGBTQ workers are out to at least one coworker, but less than half are out to their human resources department. Bloomberg

- Workers are taking fewer overtime shifts, reducing the average workday by 37 minutes. Productivity, however, remains the same. Financial Advisor

- Even at companies where A.I. is banned, employees are boosting their productivity by secretly using the technology. Business Insider

- New data shows that the labor market is slowly cooling and rebalancing itself without the threat of additional layoffs or a recession. Axios

Watercooler

Everything you need to know from Fortune.

Global 500. The 2023 Fortune Global 500 ranking is out today. Fifty-seven companies employ at least 300,000 people worldwide, led by Walmart, with 2.1 million employees.

Discrimination weighs heavily. C-suite execs are showing a newfound interest in fitness and getting ripped. The trend might shed light on new workplace beauty standards that often leave women vulnerable. —Paige Hagy

RTO backfires. A handful of new reports shed light on companies' internal struggles after mandating a return to office. In one survey, employees likened the displeasure of an office return to taking a 2% to 3% pay cut. —Gleb Tsipursky

Language link. Workers in English-speaking countries spend more time working from home, and it has little to do with national income. —Jane Thier

This is the web version of CHRO Daily, a newsletter focusing on helping HR executives navigate the needs of the workplace. Sign up to get it delivered free to your inbox.

About the Authors
By Paige McGlauflin
LinkedIn icon
See full bioRight Arrow Button Icon
By Joey AbramsAssociate Production Editor

Joey Abrams is the associate production editor at Fortune.

See full bioRight Arrow Button Icon

Latest in Newsletters

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Newsletters

woman typing on a computer.
NewslettersMPW Daily
The ‘AI gender gap’ narrative is missing the full picture
By Emma HinchliffeApril 9, 2026
7 hours ago
Even Nvidia’s own research teams can’t get enough GPUs amid the race for AI computing power
NewslettersEye on AI
Even Nvidia’s own research teams can’t get enough GPUs amid the race for AI computing power
By Sharon GoldmanApril 9, 2026
7 hours ago
Senior executive team together in conference meeting room in contemporary modern office bright sunny daylight sunset dusk talking discussing planning organizing strategy.
NewslettersCFO Daily
The white-collar jobs most exposed to AI, according to Anthropic’s own data
By Sheryl EstradaApril 9, 2026
11 hours ago
Bobby Healy stands in front of a Manna drone with his arms crossed.
NewslettersTerm Sheet
ARK Invest is betting on underdog drone delivery company Manna to beat out Alphabet and Zipline
By Lily Mae LazarusApril 9, 2026
12 hours ago
Why CEO Michelle Gass is thriving at Levi’s after stumbling at Kohl’s
NewslettersCEO Daily
Why CEO Michelle Gass is thriving at Levi’s after stumbling at Kohl’s
By Phil WahbaApril 9, 2026
13 hours ago
Meta chief AI officer Alexandr Wang in New Delhi on February 19, 2026. (Photo: Ludovic Marin/AFP/Getty Images)
NewslettersFortune Tech
Meta takes the wraps off Muse Spark
By Andrew NuscaApril 9, 2026
13 hours ago

Most Popular

The U.S. government is spending $88 billion a month in interest on national debt—equal to spending on defense and education combined
Economy
The U.S. government is spending $88 billion a month in interest on national debt—equal to spending on defense and education combined
By Fortune EditorsApril 9, 2026
12 hours ago
The U.S. had a national debt ‘home run’ in its grasp, says Jamie Dimon. But the government did nothing, and now its best option is crisis management
Economy
The U.S. had a national debt ‘home run’ in its grasp, says Jamie Dimon. But the government did nothing, and now its best option is crisis management
By Fortune EditorsApril 8, 2026
2 days ago
2 years ago, Saudi Arabia quietly canceled the ‘petrodollar’ deal with America that wired the world economy for 50 years. Then war broke out in Iran
Energy
2 years ago, Saudi Arabia quietly canceled the ‘petrodollar’ deal with America that wired the world economy for 50 years. Then war broke out in Iran
By Fortune EditorsApril 7, 2026
2 days ago
Self-made billionaire MrBeast says his work-life balance is nonexistent and calls it a ‘miracle’ if he works less than 15-hour days: ‘I live to work’
Success
Self-made billionaire MrBeast says his work-life balance is nonexistent and calls it a ‘miracle’ if he works less than 15-hour days: ‘I live to work’
By Fortune EditorsApril 8, 2026
1 day ago
Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout
AI
Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout
By Fortune EditorsApril 8, 2026
1 day ago
Gen Z doesn't want your full-time job. They want several part-time roles, and it's reshaping the entire workforce
Success
Gen Z doesn't want your full-time job. They want several part-time roles, and it's reshaping the entire workforce
By Fortune EditorsApril 9, 2026
15 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.