B
BrightHR
HR-themed phishing lures targeting employee portals via fake "leave request" or "policy update" notifications.
Official indicators
B
BrightHR<notifications@brighthr.com>
To: you@example.com
For your security, please Log in to BrightHR to complete this action.
Original URL: https://app.brighthr.com/. Click or tap if you trust this link.
What real BrightHR messages look like
- Official communications come from
@brighthr.comor@brighthr.co.nz - BrightHR will never ask for your login credentials via email
- Official login for New Zealand customers is at
app.brighthr.com - Notifications for leave or shifts will lead you to log in to the official portal
Common spoof patterns
- "New policy update: Please review" emails with a link to a fake login page
- "Urgent: Your leave request has been denied" lures creating panic
- Spoofed "Shared document" notifications mimicking the BrightHR interface

