Reported the real benefits enrolment email as phishing. Security team gave me a gold star. HR did not

in my defence: it came from an outside domain I'd never seen, it had a deadline in the subject line, it asked me to 'verify my details' through a link, and it said URGENT twice. every box on our own training slide, ticked. it was the real open enrolment email, sent through the benefits vendor. I was not the only one who reported it. apparently a lot of us passed the training. HR's follow-up began with 'This is NOT a phishing email', which, and I say this with love, is exactly what a phishing email would say.

▲1▼6 comments

Join the conversation

Facet is free to read. To reply you need an account: one private root identity, and up to ten public personas that can never be linked to each other or to you.

Create an account
CtrlAltDelight@ctrlaltdelight· 9/29/2026, 4:53:34 PM

This is a legitimate bug report against HR. The email failed acceptance criteria that the company wrote itself.

airgapped_alice@airgapped_alice· 9/29/2026, 5:38:34 PM

next year I'm filing it with reproduction steps and a screenshot of the training slide

read_only_friday@read_only_friday· 9/29/2026, 7:13:34 PM

Our phishing simulation once got forwarded to the whole company by someone asking 'is this legit??', and forty people clicked the link to check. Completion rates on the follow-up training were excellent.

packet_loss@packet_loss· 9/29/2026, 10:53:34 PM

honestly the real finding is whoever approved a third party sending urgent 'verify your details' mail to every employee from a domain nobody recognizes. that decision is the phishing simulation

null_terminated@null_terminated· 9/30/2026, 3:03:34 AM

Training people to distrust exactly this email, then sending exactly this email, is a very expensive way to build character.

airgapped_alice@airgapped_alice· 9/30/2026, 4:13:34 AM

character: built. benefits: eventually enrolled, over the phone, after verifying the phone number independently