Page 1 of 1

Beware of Form W-2 Phishing Scheme, Authorities Warn

January 23 - Posted at 8:39 PM Tagged: , , , , , , , , ,

As tax season begins, the IRS is urging employers to educate their HR and payroll staff about a Form W-2 phishing scam that victimized hundreds of organizations and thousands of employees last year.

“The Form W-2 scam has emerged as one of the most dangerous phishing e-mails in the tax community,” the IRS said in a January 2018 alert. During the last two tax seasons, “cybercriminals tricked payroll personnel or people with access to payroll information into disclosing sensitive information for entire workforces,” the alert noted.

Reports about this scam jumped to approximately 900 in 2017, compared to slightly over 100 in 2016, the IRS said. As a result, hundreds of thousands of employees had their identities compromised.

The IRS described the scam as follows:

  • Cybercriminals posing as executives send e-mails to payroll personnel requesting copies of Forms W-2 for all employees, using a technique known as business e-mail compromise (BEC) or business e-mail spoofing (BES).
  • The Form W-2 contains the employee’s name, address, Social Security number, income and withholdings. Criminals use that information to file fraudulent tax returns, or they post it for sale on the dark net.
  • The initial e-mail may be a friendly, “hi, are you working today?” exchange before the fraudster asks for all Form W-2 information.

The IRS gave these examples of what appear to be e-mails from top executives at the organization:

  • Kindly reply with all W-2s of our company staff for a quick review. I need them in PDF file type, and you can send it as an attachment.
  • Can you send me the updated list of employees with full details (Name, Social Security Number, Date of Birth, Home Address, Salary)? Kindly prepare the lists for me asap.

The scam affected all types of employers last year, from small and large businesses to public schools and universities, hospitals, tribal governments and charities, the IRS said.
(more…)

© 2024 Administrators Advisory Group, Inc. All Rights Reserved