Don’t Fall for the Trap: Spotting Seasonal Phishing Scams

October 6, 2026
Open enrollment, early holiday shopping, and year-end tasks bring plenty of messages competing for our attention. Scammers can use those familiar activities as cover, impersonating employers, delivery services, retailers, and government agencies. Phishing messages try to persuade you to reveal sensitive information, open a harmful attachment, or visit a fraudulent website. Similar tactics appear in […]

Open enrollment, early holiday shopping, and year-end tasks bring plenty of messages competing for our attention. Scammers can use those familiar activities as cover, impersonating employers, delivery services, retailers, and government agencies.

Phishing messages try to persuade you to reveal sensitive information, open a harmful attachment, or visit a fraudulent website. Similar tactics appear in shopping and job scams, where the goal may be to steal money as well as information.

These schemes occur throughout the year. As fall routines get underway, the following scenarios are useful reminders to pause and verify before acting.

1. Fake HR and Open Enrollment Messages

A benefits deadline can make an urgent message seem believable. A scammer may impersonate your HR department or benefits provider and claim that you must act immediately to avoid losing coverage.

What to watch for: An unexpected request to confirm benefit selections, update payroll information, or sign in through an unfamiliar link. A fake login page may capture your password or other sensitive information.

What to do: Open your employer’s benefits portal through a trusted bookmark or established internal resource. If the request is unexpected, contact HR through a known channel. Check the full sender address, but do not rely on the display name, logo, or appearance of the message as proof that it is genuine.

2. Package Delivery Text Scams

A text claiming that a package has an incomplete address or requires a small redelivery payment can be convincing when you are expecting an order.

What to watch for: An unsolicited message directing you to a link to correct delivery information or provide card details. A small requested payment can be a way to collect financial information.

What to do: Check the order through the retailer’s app or website, or enter a known tracking number directly on the carrier’s official website. Avoid using links in an unexpected text.

Legitimate delivery notifications may exist, particularly when you have requested them. The safer approach is to verify the shipment independently rather than assume a message is genuine because it names a familiar carrier.

3. Unexpected Tax Refunds or Payment Demands

Tax-related scams are not limited to filing season. Messages promising an unexpected rebate or threatening immediate consequences for unpaid taxes can create pressure to respond.

What to watch for: A message asking you to provide a Social Security number, enter banking information to claim a refund, or make an immediate payment through an unusual method.

What to do: Visit IRS.gov or the relevant state tax agency’s official website directly. Use independently verified contact information to check the claim.

The IRS states that it does not send emails or text messages without permission and does not send direct messages through social media. A claimed government connection is a reason to verify the request—not a reason to trust it.

4. Fake Shopping Deals and Seasonal Job Offers

Early holiday promotions and seasonal hiring can provide convincing settings for fraudulent offers.

What to watch for: Unfamiliar stores advertising unusually deep discounts, or job offers promising substantial pay for very little work. A supposed employer may demand an upfront payment or send a check and instruct you to use the proceeds to purchase equipment or send money elsewhere.

What to do: Verify a retailer or employer independently before sharing information. Check a job listing through the company’s official careers page and research unfamiliar sellers using multiple sources.

Do not pay for the promise of a job. An employer’s check followed by instructions to send money back or buy gift cards is a warning sign of a fake-check scam.

Warning Signs Worth a Second Look

Different scams often share the same tactics:

  • Pressure to act immediately: Threats of lost benefits, suspended accounts, or missed deliveries are designed to rush your decision.
  • Unexpected requests for sensitive information: Be cautious when a message asks for passwords, verification codes, banking details, or identifying information.
  • Mismatched addresses or links: Lookalike domains and unfamiliar destinations warrant further checking. A polished website or secure connection does not, by itself, prove legitimacy.
  • Unusual payment instructions: An unexpected demand for payment exclusively by gift card, cryptocurrency, wire transfer, or payment app is a serious warning sign.
  • Requests that bypass normal processes: Instructions to keep a request secret or avoid established approval channels deserve independent verification.

Good spelling and familiar branding are not guarantees. Focus on what the message asks you to do and whether you can confirm that request through a trusted channel.

If You Have Already Responded

If you interacted with a suspicious message on a work account or device, notify your IT or security team promptly and follow your organization’s reporting process. Tell them whether you clicked a link, opened an attachment, entered information, or approved a login request.

If you disclosed a password, change it through the legitimate service and change it on any other account where you reused it. Enable multifactor authentication where available.

If you shared financial information or sent money, contact your bank, card issuer, or payment provider promptly. For exposed personal information, visit IdentityTheft.gov for recovery guidance. You can also report scams at ReportFraud.ftc.gov.

Make Verification a Habit

Before responding to an unexpected request, pause and check it through a website, app, or contact method you already trust.

For organizations, reinforce that habit with clear reporting channels and reminders tied to activities employees recognize, such as open enrollment. A timely report gives the security team an opportunity to investigate and respond.

A few moments of independent verification can help protect your information—and your organization’s.

We're Here to Help

Recognizing phishing attempts is one part of an effective cybersecurity program. Clear reporting procedures, employee education, and coordinated response practices help organizations put that awareness into action.

Have questions about strengthening your organization’s cybersecurity awareness and risk-management approach? Connect with the Asurity Advisors team to discuss your needs.

Additional Resources

FTC: Job Scams

FTC: How to Recognize and Avoid Phishing Scams

U.S. Postal Inspection Service: Package Tracking Text Scams

IRS: Report Fake IRS, Treasury, or Tax-Related Messages

Sign up for news + updates

Expert insights and regulatory updates on RegTech, compliance management, and fair lending.

Recommended Resources

What Sets RegCheck Apart

Discover how RegCheck® delivers smarter mortgage compliance reviews through loan-specific testing, configurable compliance logic, built-in expertise, and support for evolving industry standards.

Propel Smarter DSCR Lending — Built for Investor Success

Discover how Propel™ streamlines DSCR loan production. Generate compliant DSCR documentation nationwide, close faster, and scale investor lending with seamless integration and compliance-first automation.

Propel™ by Asurity - Case Study: Proprietary LOS Integration

Find out why a top-ten mortgage lender with a proprietary loan origination system (LOS) needed to convert from a legacy document platform.

chevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram