A BrightHR Phishing Campaign Is Targeting HR Professionals in New Zealand
A phishing campaign targeting HR professionals uses deceptive BrightHR termination briefings to drive credential harvesting.
A phishing campaign impersonating BrightHR, a cloud-based HR software platform, has been identified targeting HR professionals and business operators across New Zealand. The emails arrive from the domain learn-brighthr.com, a lookalike domain constructed to mimic legitimate BrightHR communications. The subject line references employment termination scenarios framed as a scheduled learning event, a social engineering technique designed to create a sense of urgency and professional relevance among recipients responsible for workforce management.
The sender address theteam@learn-brighthr.com is not affiliated with BrightHR's verified sending infrastructure. The use of a hyphenated lookalike domain is a well-documented tactic employed to bypass casual sender inspection, particularly in environments where email security controls do not enforce strict domain authentication checks such as DMARC, DKIM, and SPF validation. Organisations that rely on BrightHR for HR administration are the most likely intended targets, as the lure is contextually plausible to that user base.
The subject matter — termination scenario management — is deliberately chosen to resonate with HR practitioners who routinely engage with compliance-focused training content. This specificity suggests the threat actors have conducted some degree of reconnaissance into the professional responsibilities of their intended recipients, or are broadly targeting known BrightHR customer segments. Clicking through such lures typically leads to credential harvesting pages, malicious file downloads, or further social engineering sequences.
Organisations that use BrightHR or distribute HR-related training communications internally should verify all such emails against known sender domains and implement user awareness guidance specific to lookalike domain detection. Email filtering rules that flag hyphenated brand-mimicking domains should be reviewed and updated where applicable. Any recipient who has interacted with this email should treat their credentials as potentially compromised and initiate appropriate internal response procedures.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Where a reply to this message would actually be delivered. When it differs from the visible From address, an unsuspecting reply lands with the attacker instead.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
• Verify the sender. Legitimate BrightHR communications will typically originate from @brighthr.com. This lure uses a deceptive learn-brighthr.com domain.
• Do not engage with the link. Avoid clicking Register or other links in unsolicited HR briefings.
• Report to CERT NZ. Report the incident via their website at cert.govt.nz.
• Internal Escalation. Notify your internal HR and IT departments.
See what a genuine BrightHR message looks like, the real sender domain, the real link destination, and where to report a fake.



