Back to The Local Vocal
The Local VocalMedium
PhishingBrightHR
Email
Medium risk PhishingEncountered ViaEMAIL 20 July 2026
RegionNew Zealand

A BrightHR Phishing Campaign Is Targeting HR Professionals in New Zealand

A phishing campaign targeting HR professionals uses deceptive BrightHR termination briefings to drive credential harvesting.

A phishing campaign impersonating BrightHR, a cloud-based HR software platform, has been identified targeting HR professionals and business operators across New Zealand. The emails arrive from the domain learn-brighthr.com, a lookalike domain constructed to mimic legitimate BrightHR communications. The subject line references employment termination scenarios framed as a scheduled learning event, a social engineering technique designed to create a sense of urgency and professional relevance among recipients responsible for workforce management.

The sender address theteam@learn-brighthr.com is not affiliated with BrightHR's verified sending infrastructure. The use of a hyphenated lookalike domain is a well-documented tactic employed to bypass casual sender inspection, particularly in environments where email security controls do not enforce strict domain authentication checks such as DMARC, DKIM, and SPF validation. Organisations that rely on BrightHR for HR administration are the most likely intended targets, as the lure is contextually plausible to that user base.

The subject matter — termination scenario management — is deliberately chosen to resonate with HR practitioners who routinely engage with compliance-focused training content. This specificity suggests the threat actors have conducted some degree of reconnaissance into the professional responsibilities of their intended recipients, or are broadly targeting known BrightHR customer segments. Clicking through such lures typically leads to credential harvesting pages, malicious file downloads, or further social engineering sequences.

Organisations that use BrightHR or distribute HR-related training communications internally should verify all such emails against known sender domains and implement user awareness guidance specific to lookalike domain detection. Email filtering rules that flag hyphenated brand-mimicking domains should be reviewed and updated where applicable. Any recipient who has interacted with this email should treat their credentials as potentially compromised and initiate appropriate internal response procedures.

Email authorisation
SPF
pass
DKIM
pass
DMARC
pass
COMPAUTH
pass
Sender Domain Intelligence

The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.

Sender domainlearn-brighthr.com
Age15 daysNewly registered
Registered12/07/2026
Replies to this message would not go back to the sender. They would be routed to brighthr.ca.
Reply-To Domain Intelligence

Where a reply to this message would actually be delivered. When it differs from the visible From address, an unsuspecting reply lands with the attacker instead.

Reply-To domainbrighthr.ca
Email Sample
Source
Decision1
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

Verify the sender. Legitimate BrightHR communications will typically originate from @brighthr.com. This lure uses a deceptive learn-brighthr.com domain.

Do not engage with the link. Avoid clicking Register or other links in unsolicited HR briefings.

Report to CERT NZ. Report the incident via their website at cert.govt.nz.

Internal Escalation. Notify your internal HR and IT departments.

BrightHR logo
Is it real?
Got an email from BrightHR?

See what a genuine BrightHR message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing