Skip to main content
ThreatPhishing & impersonation

Fake HSA or FSA administrator claiming the health savings or flexible spending account balance will be forfeited if funds are not spent or claimed before the deadline — advance-fee or credential-harvest fraud; real HSA/FSA deadline communications come through authenticated benefit portals or postal notices, never cold email links claiming imminent forfeiture.

hsa-fsa-benefit-expiry-phish

What this tier means

High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.

How Gorganizer detects this

Fake HSA or FSA administrator (impersonating HealthEquity, WEX Health, Optum Bank, PayFlex, or Benefytt) claiming the recipient's health savings or flexible spending account balance will be forfeited if they do not spend or claim the remaining funds before the use-it-or-lose-it deadline — advance-fee or credential-harvest fraud targeting employee benefit anxiety. Real HSA/FSA administrators communicate account deadlines through authenticated benefit portals or postal notices; cold emails claiming funds will be forfeited unless the recipient clicks a link to "spend" or "claim" funds are either advance-fee fraud (leading to a fake spending portal that harvests payment details) or credential-harvest attacks. Distinct from employee-benefits-open-enrollment-phish (employer open enrollment period) and healthcare-insurance-sbc-phish (SBC document) — this targets the HSA/FSA balance-forfeiture / use-it-or-lose-it deadline narrative. Detection: HSA/FSA/health savings/flexible spending account balance + forfeit/expire/deadline/spend/claim vocabulary + no List-Unsubscribe + no In-Reply-To + not protected sender. Trash score: +3. Source: GC1-R26; IRS FSA use-or-lose rules (Rev. Rul. 2005-24); EBSA benefit account fraud advisory; FTC health benefit scam patterns 2025.

False-positive guard

Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.

About the scoring engine

Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.

Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.

Ready to clean your inbox?

Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.

Get started