Kaspersky has identified a new phishing campaign targeting employees, using personalised emails that appear to be HR policy updates. Unlike standard scams, these messages tailor to each recipient. Both the email and the attached document include the employee’s name, making them seem more legitimate. This level of customisation marks a major escalation in phishing tactics. The ultimate goal is to steal corporate email credentials.
According to researchers, the attackers likely gathered employee names in advance to personalise each message. The emails are particularly deceptive, featuring a fake ‘verified sender’ badge, the recipient’s name, and a prompt to review updates related to remote work, benefits administration, and security policies.
However, the body of the email is actually an image rather than real text – a tactic designed to bypass standard email filters.
The attached file, disguised as an updated “Employee Handbook,” contains no real policy updates. It includes a title page, a table of contents with supposed changes marked in red, and a page featuring a QR code.
There are also basic instructions on how to scan the code. The document repeats the recipient’s name several times to make it seem personalised and legitimate. If the recipient scans the QR code, they are taken to a fake website. There, they are asked to enter their corporate login details—exactly what the attackers are after.
Roman Dedenok, Anti-Spam Expert at Kaspersky, says the campaign reflects a new level of phishing sophistication. He believes it likely uses automation to generate a separate email image and attachment for each target. This method helps the attackers reach more people while slipping past many traditional security systems.
“This campaign demonstrates a new level of sophistication in phishing attacks. We may be seeing a new type of mailing automation that generates individual documents and image-based emails for each recipient. This method helps scale the attack while possibly avoiding traditional security filters,” said Roman Dedenok, Anti-Spam Expert at Kaspersky. “Organisations must take proactive steps to defend against these advanced threats.”
To mitigate the risk, Kaspersky advises organisations to implement advanced email security solutions at the server level, ensure all employee devices have robust protection, and provide regular training on the latest phishing tactics.
Staff should be encouraged to look out for warning signs such as image-based emails, mismatched document names, and to verify unusual requests with HR directly.





