HR News | Employer's Guardian

Open Enrollment Scam: What Employers Need to Know

Written by Admin | Aug 18, 2026, 3:39:05 PM

An open enrollment scam is a fraud campaign timed to the annual benefits enrollment window, when every employee is expecting unfamiliar messages about coverage, deadlines, and required actions. The season hands attackers the three conditions they otherwise have to manufacture: a plausible pretext, genuine urgency, and a workforce primed to comply.

For eleven months, an email demanding that employees log in and confirm their personal details is suspicious. During enrollment, it is expected. That inversion is the entire scam.

The forms it takes

The fake portal. A message — branded convincingly as the employer, the benefits platform, or a carrier — links to a replica enrollment site. Employees enter credentials and then, because enrollment legitimately asks for it, a full data set: their identifiers, and their dependents' names, Social Security numbers, and birth dates. The dependent data is the prize; children's identities can be misused for years before anyone looks.

The deadline threat. "Complete this step within 24 hours or lose coverage for the year." The threatened loss of health insurance is among the most reliable motivators available, and it suppresses exactly the pause in which people notice something is wrong.

The confirmation harvest. A message asking employees to "verify" details on file — each verification a data point handed over.

The account takeover. Credentials phished during the season are used on the real platform: contact details changed first to suppress alerts, then reimbursement banking redirected or spending accounts drained.

The benefits-adjacent call. Phone and text variants impersonating HR or the carrier, walking employees through "completing enrollment" — which is to say, through surrendering access.

Why communication design is the defense

The technical controls matter — MFA on the platform, notifications on detail changes — but the scam lives or dies on whether employees can distinguish real enrollment communications from fake ones. That is determined by how the employer communicates, and most employers make it impossible.

An organization that sends enrollment emails from varying addresses, through multiple vendors, each containing login links, has trained its workforce that benefits mail looks like anything and always contains a link. Its employees cannot tell the real from the fake, because structurally there is no difference.

The fixes are choices, not products:

  • Announce the season before it starts — which platform, which sender addresses, what steps will be required, and what will never be asked
  • Send no links. Direct employees to navigate to the portal themselves or through the intranet. An employee taught that legitimate enrollment mail never contains a login link cannot be routed to a fake portal by one.
  • Use one sender, consistently, and tell employees what it is
  • Name the deadline behavior — real communications will state dates, never demand action within hours
  • Give the season a reporting channel — one address where anything odd goes, with fast answers

The vendor dimension needs checking too: if the carrier or platform sends its own mail full of links, the employer's no-links message collapses. Aligning vendor communications — or at least warning employees exactly what vendor mail will look like — is part of the preparation.

The platform-side hardening

For the takeover variant, the controls that matter sit on the enrollment platform itself: MFA required rather than optional; change notifications sent to old and new contact details, so an attacker cannot suppress alerts by updating contacts first; a hold between contact changes and any money movement; and a support desk that verifies identity through details on file before unlocking anything, because the help line is the social-engineering route of choice during the crunch.

These are configuration and contract questions to settle with the vendor before the window opens, not during it.

If employees were caught

Assume a successful campaign hit more than one person — these are sent in bulk. Reset exposed credentials and revoke sessions; have affected employees check and correct contact and banking details on the real platform; determine what data the fake site collected, since dependent identifiers may trigger notification obligations and warrant credit monitoring offers; and tell the workforce what happened in plain terms, because the fastest way to surface the unreported cases is to describe the scam and ask.

Employer's Guardian helps employers run enrollment communications, vendor coordination, and the season's security practices through outsourced HR services.

This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.