An open enrollment scam is a fraud campaign timed to the annual benefits enrollment window, when every employee is expecting unfamiliar messages about coverage, deadlines, and required actions. The season hands attackers the three conditions they otherwise have to manufacture: a plausible pretext, genuine urgency, and a workforce primed to comply.
For eleven months, an email demanding that employees log in and confirm their personal details is suspicious. During enrollment, it is expected. That inversion is the entire scam.
The fake portal. A message — branded convincingly as the employer, the benefits platform, or a carrier — links to a replica enrollment site. Employees enter credentials and then, because enrollment legitimately asks for it, a full data set: their identifiers, and their dependents' names, Social Security numbers, and birth dates. The dependent data is the prize; children's identities can be misused for years before anyone looks.
The deadline threat. "Complete this step within 24 hours or lose coverage for the year." The threatened loss of health insurance is among the most reliable motivators available, and it suppresses exactly the pause in which people notice something is wrong.
The confirmation harvest. A message asking employees to "verify" details on file — each verification a data point handed over.
The account takeover. Credentials phished during the season are used on the real platform: contact details changed first to suppress alerts, then reimbursement banking redirected or spending accounts drained.
The benefits-adjacent call. Phone and text variants impersonating HR or the carrier, walking employees through "completing enrollment" — which is to say, through surrendering access.
The technical controls matter — MFA on the platform, notifications on detail changes — but the scam lives or dies on whether employees can distinguish real enrollment communications from fake ones. That is determined by how the employer communicates, and most employers make it impossible.
An organization that sends enrollment emails from varying addresses, through multiple vendors, each containing login links, has trained its workforce that benefits mail looks like anything and always contains a link. Its employees cannot tell the real from the fake, because structurally there is no difference.
The fixes are choices, not products:
The vendor dimension needs checking too: if the carrier or platform sends its own mail full of links, the employer's no-links message collapses. Aligning vendor communications — or at least warning employees exactly what vendor mail will look like — is part of the preparation.
For the takeover variant, the controls that matter sit on the enrollment platform itself: MFA required rather than optional; change notifications sent to old and new contact details, so an attacker cannot suppress alerts by updating contacts first; a hold between contact changes and any money movement; and a support desk that verifies identity through details on file before unlocking anything, because the help line is the social-engineering route of choice during the crunch.
These are configuration and contract questions to settle with the vendor before the window opens, not during it.
Assume a successful campaign hit more than one person — these are sent in bulk. Reset exposed credentials and revoke sessions; have affected employees check and correct contact and banking details on the real platform; determine what data the fake site collected, since dependent identifiers may trigger notification obligations and warrant credit monitoring offers; and tell the workforce what happened in plain terms, because the fastest way to surface the unreported cases is to describe the scam and ask.
Employer's Guardian helps employers run enrollment communications, vendor coordination, and the season's security practices through outsourced HR services.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.