Fake HR department or benefits administrator claiming the target missed open enrollment and must click an emergency re-enrollment link within 24–48 hours or health insurance will be terminated — credential-harvest attack; real open enrollment is managed through authenticated employer HR portals, never cold email emergency enrollment links.
benefits-open-enrollment-emergency-phish
What this tier means
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
How Gorganizer detects this
Fake HR department or benefits administrator (impersonating Aetna, Anthem, UnitedHealthcare, CIGNA, Kaiser Permanente, or generic "HR Benefits") claiming the target missed the annual open enrollment window and offering an emergency re-enrollment link that must be clicked within 24–48 hours to restore coverage or health insurance will be terminated — credential-harvest attack exploiting healthcare anxiety. Real open enrollment changes are managed through authenticated employer HR portals under IRS Section 125 and ERISA regulations; cold emails offering a "special emergency enrollment link because you missed open enrollment — click within 24 hours or lose coverage" are credential-harvest attacks that exploit the critical importance of health insurance. The missed open enrollment / emergency enrollment window / click within 24 hours or lose coverage pretext targets the combination of procedural complexity and health insurance anxiety. Distinct from benefits-enrollment-confirmation-phish (generic benefit confirmation pretext) — this targets the HR benefits missed open enrollment / emergency enrollment deadline / lose coverage vocabulary. Detection: missed open enrollment + emergency enrollment link + click within 24-48 hours + or lose coverage + no List-Unsubscribe + no In-Reply-To + not protected sender. Trash score: +4. Source: GC1-R30; FTC health insurance scam advisory 2025; ERISA Section 125 open enrollment rules; CISA HR impersonation patterns; HHS employee benefits fraud bulletin.
False-positive guard
Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.
About the scoring engine
Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.
Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.
Ready to clean your inbox?
Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.
Get started