High riskEmail

HR Portal Email Scam

This scam emails employees pretending to be the HR or staff portal, asking them to log in to review a policy, payslip, or benefits update, leading to a fake page that captures work credentials for further fraud.

Quick verdict

Risk level
High risk
Scam type
Workplace impersonation phishing
Main red flag
An email pushes you to log in to the HR or employee portal via a link.
What to do first
Do not use the link. Open the portal through your usual bookmark or intranet.

What to know first

This scam emails employees pretending to be the HR or staff portal, asking them to log in to review a policy, payslip, or benefits update, leading to a fake page that captures work credentials for further fraud.

Email scams, or phishing, remain one of the most common ways criminals steal logins, payment details, and money. A convincing message imitates a brand or contact and steers you toward a fake login page, a malicious attachment, or a fraudulent payment.

The core pattern to watch for is clear: An email pushes you to log in to the HR or employee portal via a link. Do not use the link. Open the portal through your usual bookmark or intranet.

Related tricks worth knowing: the Payroll Direct Deposit Scam and the Microsoft Account Email Scam. For the wider picture, browse the Email Scams guides or run the message through our scam checker.

Scam statistics

Most reported
phishing was the most common type of cybercrime complaint reported to the FBI in 2023
$12.5B
total reported internet-crime losses in the US in 2023

Tell-tale red flags

  • A login link to the HR or employee portal
  • Pressure tied to a policy or benefits deadline
  • A login page whose address is not your company's
  • A sender address that is external or slightly off
  • Requests to 'verify' your work credentials

Staying safe

  • Open the HR or employee portal through your usual bookmark or intranet
  • Verify any request with your HR or IT team
  • Report the email to your security team
  • Enable multi-factor authentication on work accounts

How it usually reads

Example pattern, not a real report
Example pattern: 'Action required: review and acknowledge your updated benefits in the employee portal by Friday: [suspicious link]' leading to a fake login.

This is a fictional, anonymised example used to illustrate the pattern. It is not a verified real message, and any names are used only to show how the scam typically reads.

What to notice: An email pushes you to log in to the HR or employee portal via a link.

Steps if you already acted

  • If you entered your work login, tell IT and change it immediately
  • Watch for misuse of your payroll or benefits details
  • Review your account for changed direct deposit or contact details
  • Alert colleagues who may have received the same email

Common mistakes

  • Do not log in to work portals through email links
  • Do not share work credentials
  • Do not ignore a possible compromise; report it

Scams like this one

Your questions answered

Why target employee portal logins?
Work credentials can unlock payroll, personal data, and company systems, enabling direct deposit diversion and wider attacks. That makes them valuable to scammers.
How do I access the portal safely?
Use your usual bookmark or company intranet, not a link in an email, and verify unexpected requests with HR or IT.
I entered my work login. What now?
Tell your IT or security team immediately, change your password, and check for changes to your direct deposit or contact details.
How can my employer reduce this risk?
Use multi-factor authentication, train staff to verify portal links, and provide a clear way to report suspicious emails.

Last reviewed June 2026 · Written & reviewed by the

Disclaimer: This page provides educational information only to help you recognise common scam patterns. It is not legal, financial, cybersecurity, or law enforcement advice, and it does not confirm whether any specific message, company, or person is genuine or fraudulent. When in doubt, contact the official organisation directly and report concerns to your local authorities.