---
title: "Time for Your Yearly Performance Appraisal? Maybe not! | Phish Protection"
description: "Time for Your Yearly Performance Appraisal? Maybe not!: If you work at an organization, there"
image: "https://phishprotection.com/og/blog/time-for-your-yearly-performance-appraisal-maybe-not.png"
canonical: "https://phishprotection.com/blog/time-for-your-yearly-performance-appraisal-maybe-not/"
---

Quick Answer

If you work at an organization, there's a pretty good chance you're in for a yearly performance appraisal. And if you are, it's likely that someone from human resources will send you an email around that time reminding you of that. \_But beware, that email may not be what you think it is\_.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fphishprotection.com%2Fblog%2Ftime-for-your-yearly-performance-appraisal-maybe-not%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Time%20for%20Your%20Yearly%20Performance%20Appraisal%3F%20Maybe%20not!&url=https%3A%2F%2Fphishprotection.com%2Fblog%2Ftime-for-your-yearly-performance-appraisal-maybe-not%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fphishprotection.com%2Fblog%2Ftime-for-your-yearly-performance-appraisal-maybe-not%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fphishprotection.com%2Fblog%2Ftime-for-your-yearly-performance-appraisal-maybe-not%2F&title=Time%20for%20Your%20Yearly%20Performance%20Appraisal%3F%20Maybe%20not! "Share on Reddit") [ ](mailto:?subject=Time%20for%20Your%20Yearly%20Performance%20Appraisal%3F%20Maybe%20not!&body=Check out this article: https%3A%2F%2Fphishprotection.com%2Fblog%2Ftime-for-your-yearly-performance-appraisal-maybe-not%2F "Share via Email") 

![Phish Protection blog post image](https://media.mailhop.org/phishprotection/images/2019/10/protection-from-phishing-5621.jpg) 

If you work at an organization, there’s a pretty good chance you’re in for a yearly performance appraisal. And if you are, it’s likely that someone from human resources will send you an email around that time reminding you of that. _But beware, that email may not be what you think it is_.

There’s a new corporate **phishing attack** going on that involves hackers sending unsuspecting employees an email notifying them of their upcoming performance appraisal. _The hacker’s use of social engineering in this attack is very clever because they convince the victims that the appraisal is mandatory and that they might get a pay raise_. So, pretty much everyone who receives it will respond to it.

According to [Kaspersky Labs](https://www.kaspersky.com/blog/performance-appraisal-spam/28924/), “The employee receives a message that appears to be from HR, recommending a performance appraisal. The text of the message contains a link to a website with an appraisal form to be filled out.

The user must follow the link, log in, wait for an e-mail with additional details, and select one of three options. If the employee opens the link, they will see an HR portal login page. The victim is asked to enter their username, password, and e-mail address. By clicking the Sign In or Appraisal button, _the employee actually forwards the data to the cybercriminals._”

This is a classical phishing campaign that highlights why **phishing emails** so easily fool people. _It combines an ordinary fake website with a compelling email that almost everyone who receives it will respond to_. All the **phishing awareness training** in the world will not prevent some (or most) of the recipients from clicking on the link in that email and entering their credentials. Within the context of working at an organization, receiving an email like this makes too much sense to question it.

If you want to [prevent phishing](/) attacks like this from being successful at your organization, _you’re going to need some help. Help that doesn’t get fooled so easily_. And that help comes in the form of [anti-phishing software](/).

![Protection from phishing](https://media.mailhop.org/phishprotection/images/2019/10/protection-from-phishing-5621.jpg) 

**Anti-phishing software** doesn’t fall for cleverly-worded phishing emails because it doesn’t read them. _It only cares about the link in the email: what it is and where it points to_.

To protect the employees at your organization from deceptive phishing emails like the performance appraisal ones, check out anti-phishing software from [Phish Protection](/). Phish Protection doesn’t read the emails. _It simply checks for malicious attachments AND malicious links_, and if it finds any, it keeps you from clicking on them.

Phish Protection is **cloud-based anti-phishing software** that requires no software or hardware to buy. It sets up in 10 minutes, costs pennies per email per month and comes with 24/7 live technical support.

## Topics

[ Phishing ](/tags/phishing/) 

![Brad Slavin](https://media.mailhop.org/phishprotection/images/authors/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead across DuoCircle's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Protect your inbox from phishing attacks

Real-time email security with 60-day free trial. No credit card required.

[Start Free Trial](https://portal.duocircle.com/cart.php?a=add&pid=101&brand=phishprotection) [View Pricing](/pricing/) 

## Related Articles

[  Foundational 5m  0ktapus, Okta Breach Helps Attackers Launch Sophisticated Supply Chain Attacks  Sep 5, 2022 ](/blog/0ktapus-okta-breach-helps-attackers-launch-sophisticated-supply-chain-attacks/)[  Foundational 4m  13 Spear Phishing Attacks Examples To Justify Investment For Phishing Prevention Solutions In Your Organization  Aug 1, 2019 ](/blog/13-spear-phishing-attacks-examples-to-justify-investment-for-phishing-prevention-solutions-in-your-organization/)[  Foundational 4m  All 14 centers of Kettering Health were affected by a massive ransomware attack, Major outage in the Ohio medical center  May 23, 2025 ](/blog/14-centers-of-kettering-health-were-affected-by-massive-ransomware-attack-in-ohio-medical-center/)[  Foundational 4m  2021 Phishing Trends You Need To Be Wary Of  Aug 2, 2021 ](/blog/2021-phishing-trends-to-be-wary-of/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://github.com/duocircle"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://phishprotection.com/contact/"},"knowsAbout":["Phishing Protection","Email Security","Anti-Phishing","Business Email Compromise","Ransomware Protection","Time of Click Protection","Office 365 Email Security","Advanced Threat Defense"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"Phish Protection","url":"https://phishprotection.com","description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","publisher":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Time for Your Yearly Performance Appraisal? Maybe not!","description":"Time for Your Yearly Performance Appraisal? Maybe not!: If you work at an organization, there's a pretty good chance you're in for a yearly performance.","url":"https://phishprotection.com/blog/time-for-your-yearly-performance-appraisal-maybe-not/","datePublished":"2019-10-23T06:37:48.000Z","dateModified":"2026-04-17T15:43:10.000Z","dateCreated":"2019-10-23T06:37:48.000Z","author":{"@type":"Person","@id":"https://phishprotection.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://phishprotection.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/phishprotection/images/authors/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://github.com/duocircle"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://phishprotection.com/contact/"},"knowsAbout":["Phishing Protection","Email Security","Anti-Phishing","Business Email Compromise","Ransomware Protection","Time of Click Protection","Office 365 Email Security","Advanced Threat Defense"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://phishprotection.com/blog/time-for-your-yearly-performance-appraisal-maybe-not/"},"articleSection":"foundational","keywords":"Phishing","wordCount":459,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/phishprotection/images/2019/10/protection-from-phishing-5621.jpg","caption":"Phish Protection blog post image","width":1200,"height":630},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://phishprotection.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://phishprotection.com/blog/"},{"@type":"ListItem","position":3,"name":"Foundational","item":"https://phishprotection.com/foundational/"},{"@type":"ListItem","position":4,"name":"Time for Your Yearly Performance Appraisal? Maybe not!","item":"https://phishprotection.com/blog/time-for-your-yearly-performance-appraisal-maybe-not/"}]}
```
