← Blog

The benefits email your team is already expecting

Tenant Strike4 min read

For six weeks, everyone expects email about their health plan and 401(k). The lure doesn't need a story — just a link that asks for the Microsoft 365 login.

Open enrollment at a 25-person company usually starts with one message from whoever handles HR: here's the new plan, here's what changed, here's the deadline. For the six weeks after that, everyone in the building is expecting email about their health coverage, their 401(k) and their paycheck — often from companies they've never dealt with directly, because the broker, the payroll provider and the insurer are three separate outfits.

That expectation is the attack.

A fake password-reset email has to invent a problem. A benefits email invents nothing. It only has to claim something went wrong inside a process that is genuinely happening. One write-up of this season, published on October 1, put it well: "A generic password-reset lure has to create a problem. An open enrollment lure only has to claim there's a problem inside a process that's already happening."

It isn't after your benefits. It's after your email.

Okta's threat intelligence team has been tracking one of these operations since October 2025. The emails carry subject lines like "Employee Benefits Alert - New Changes Effective Now", sent from addresses built to read correctly at a glance — one example in their report is ADP BENEFITS <[email protected]>. Since July 2026 the same group has been sending the links by text message as well as email.

The page at the end of the link does not ask about your health plan. It asks for the Microsoft 365 sign-in. And it sits in the middle, passing whatever you type straight through to the real Microsoft login as you type it — so it collects the password, the six-digit code from the authenticator app, and the session token Microsoft hands back afterwards.

The token is the valuable part. It's what keeps someone signed in as your bookkeeper without ever needing a code again. We've written separately about why that middle-man technique gets past ordinary multi-factor authentication.

So the benefits email is the door. The mailbox is the room — and a mailbox that handles invoices is where the money actually goes missing.

Why your spam filter may wave it through

Researchers at Abnormal Security documented a version that runs through a real Dropbox account. The employee gets a genuine Dropbox notification about a document on salary increases and enrollment elections; the malicious link lives inside the hosted document, not in the email. The email really is from Dropbox. There's nothing for the filter to object to.

That's the pattern worth noticing — the convincing lures borrow context you already have rather than inventing their own. Abnormal's 2026 attack landscape report, published in April, found phishing made up 58% of roughly 800,000 attacks it observed across more than 4,600 organizations.

And the benefits data is worth taking on its own merits. A benefits account holds Social Security numbers, home addresses, dependents, compensation, and often bank or beneficiary details. One vendor breach during the 2024 enrollment season exposed records for 232,506 people, according to a write-up by ThreatLocker.

Three things, before HR sends anything

Send one sentence first. Something like: "All benefits messages this year come from Dana, and the only link will be [your portal]. Anything else, forward it to me before you click." Five minutes to write. It's the highest-value item here, because it turns a judgment call into a comparison — people stop asking "does this look real?" and start asking "is this the one place it was supposed to come from?"

Put the real dates in that same message. Ask your broker for the actual enrollment window and pass it on. Nearly every one of these lures leans on a final-day urgency your plan year doesn't have, and a team that knows the real deadline has a free tell.

Ask your IT provider for two things by name. First, phishing-resistant multi-factor authentication — passkeys or Windows Hello — for anyone who touches money or sends email on behalf of others. It's the one form of MFA the middle-man page can't replay. Second, ask them to walk you through how they'd revoke every active session on one account, and how long it would take. That answer decides whether a stolen token is a bad afternoon or a bad quarter.

If you want to see which of those routes are open in your own setup, Tenant Strike maps the break-in paths real attackers use onto your own Microsoft 365 configuration. It's read-only, and there's nothing to install.

AI-researched from public sources. We label AI-assisted writing — see our trust page.

See your own risk

Want this for your own Microsoft cloud?

Tenant Strike finds the security gaps in your Microsoft 365 and Azure, shows how they chain into a real break-in, and hands you a plain-English fix for every one — read-only, and it never asks for permission to change anything. Start a 7-day Pro trial — no credit card.