How Scammers Use Fake HR Emails to Steal Passwords
The Fake HR Case File: How login spoofing steals your email credentials
A phishing email disguised as an HR compliance notice is tricking employees into handing over their Microsoft login — here’s how the scam works and how to spot it.
Key takeaways
- Scammers impersonate internal HR departments with alarming case logs that route users to fake Microsoft sign-in screens.
- Multi-factor authentication stops stolen passwords from granting access, while direct verification prevents initial clicks.
- Verify suspicious compliance messages with HR directly through a known phone number or separate message thread.
An email lands in your inbox that looks like it came straight from HR or compliance. The subject line reads “Reminder: employer opened a non-compliance case log,” and the message claims a code-of-conduct review has been opened against you. Attached is a PDF with a link to “review additional documentation.”
It’s not real. This is a phishing scam built on login spoofing, one of the more effective credential theft tactics in use right now, and one worth recognizing before it lands in your inbox.
How the scam plays out
Selecting the link in the PDF doesn’t take you to a document. It routes you through a series of fake “security checks”, entering your email address, completing a CAPTCHA, designed to make the process feel legitimate. At the end, you’re dropped onto what looks like a Microsoft sign-in page and asked to log in to access the file.
None of it is real. The security checks are theater, and the login page is a forgery. Login spoofing works by cloning a trusted site’s authentication page: Logos, fonts, layout. All copied so that typing your credentials in feels indistinguishable from a normal sign-in. It isn’t, you’re sending your password straight to the attacker.
Why this particular scam works
The premise is the mechanism. Threatening a code-of-conduct violation or HR investigation is deliberately chosen to produce fear and urgency, the two states most likely to make someone skip their normal skepticism and click before thinking.
“If they can make you panic, you’re more likely to make a mistake.”
How to avoid it
- Pause and verify the source. Don’t open the attachment or click the link. Contact your manager or HR directly through a channel you already trust, not a number or address from the email.
- Inspect the URL. Spoofed login pages often use near-miss domains —
login-micros0ft.cominstead ofmicrosoft.comcheck the address bar before typing a password. - Question unusual security steps. Real internal documents don’t route you through CAPTCHAs and a fresh login just to open a file. Convoluted access flows are a red flag on their own.
- Turn on Multi-Factor Authentication (MFA). Turning on MFA ensures that a stolen password alone is insufficient for an attacker to gain access to your account.
Keep your emotions in check. Any unexpected email with an attachment that feels urgent, threatening, or high-stakes deserves extra scrutiny, not less.
The bottom line
No legitimate HR or compliance notice requires you to run a gauntlet of security checks and a fresh login just to view a PDF. If an email is engineered to make you panic first and think second, that’s the scam working as designed. Verify through a trusted channel—in person, via a phone call using a verified directory, or through a separate message thread before you click.
