Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

Cybersecurity Alert: W-2 Scam Targeting Businesses

Author: Scarinci Hollenbeck, LLC

Date: April 27, 2017

Key Contacts

Back

IRS issues warning regarding cybercriminals and a new W-2 scam

Businesses should be vigilant about their cybersecurity this tax season. The Internal Revenue Service (IRS) issued a new warning that cybercriminals are targeting businesses with a Form W-2 phishing scam.

IRS Issues Warning On Form W-2 Scam
Photo courtesy of Stocksnap.io

W-2 Phishing Scam

On March 1, 2016, the IRS warned payroll and human resources professionals to beware of an increasingly common phishing email scheme that seeks personal information from employees under the guise of a “spoofed” email from a company executive. According to the IRS, several payroll and human resources offices have fallen for the scheme and mistakenly emailed payroll data, including W-2 forms that contain Social Security numbers and other personally identifiable information, to cybercriminals posing as company executives. The perpetrators then use the stolen personal information for monetary gain, including fraudulent tax returns for refunds.

“This is a new twist on an old scheme using the cover of the tax season and W-2 filings to try tricking people into sharing personal data. Now the criminals are focusing their schemes on company payroll departments,” said IRS Commissioner John Koskinen. “If your CEO appears to be emailing you for a list of company employees, check it out before you respond. Everyone has a responsibility to remain diligent about confirming the identity of people requesting personal information about employees.”

Cybercriminals are increasingly targeting small businesses with phishing emails, malware and other scams. To stay vigilant, companies must stay on top of emerging threats. With regard to the W-2 scam, the IRS highlights that the phishing emails share common characteristics, namely that the email purports to come from the company chief executive officer and requests a list of employees and information, including SSNs. Below are some examples of W-2 phishing scam e-mail requests:

  • “Kindly send me the individual W-2 (PDF) and earnings summary of all W-2 of our company staff for a quick review.”
  • “Can you send me the updated list of employees with full details (name, Social Security Number, date of birth, home address, salary)?”
  • “I want you to send me the list of W-2 copy of employees wage and tax statements, I need them in PDF file type, you can send it as an attachment. Kindly prepare the lists and email them to me ASAP.”

Evolving W-2 Phishing Scam

On February 2, 2017, the IRS warned that the W-2 Phishing Scam is evolving and that cybercriminals are targeting schools, restaurants, hospitals, tribal groups and others.

IRS Commissioner, John Koskinen stated that: “This is one of the most dangerous email phishing scams we’ve seen in a long time. It can result in the large-scale theft of sensitive data that criminals can use to commit various crimes, including filing fraudulent tax returns. We need everyone’s help to turn the tide against this scheme.”

The new scam includes cybercriminals who use “various spoofing techniques to disguise an email to make it appear as if it is from an organization executive. The email is sent to an employee in the payroll or human resources departments, requesting a list of all employees and their Forms W-2.  This scam is sometimes referred to as business email compromise (BEC) or business email spoofing (BES).”

The IRS advised that the latest “twist” to the W-2 scam includes a request made by the cybercriminal to the payroll or comptroller of the entity which asks that a wire transfer of funds be made to a specific account. The IRS learned that the wire transfer scam is being coupled with the W-2 phishing scam and “some companies have lost both employees’ W-2s and thousands of dollars due to the wire transfers.” 

Cybersecurity Tips to Protect Your Business

There are several steps that you can take to protect your business from the W-2 scam and other similar phishing schemes. As with any cybersecurity or data privacy measure, the key is to implement safeguards and educate staff about their importance. Below are several key tips to share with your human resources professionals:

  • Never click on links or download attachments from unknown or suspect emails.
  • Check the email, including the sender’s email address, for signs that it may be fraudulent. In many cases, the email address may contain a minor misspelling or changes in punctuation that are not apparent at first glance.
  • When in doubt, verify the request for W-2 information by placing a phone call to the requestor. Alternatively, you can forward the email to the sender’s verified email address to inquire about its authenticity.
  • To protect the sensitive information contained in W-2 forms, take steps to redact social security numbers or encrypt email messages containing tax information.

IRS Reporting Tips

The IRS urged organizations receiving a W-2 scam email to forward the suspect email to phishing@irs.gov and place “W2 Scam” in the subject line. Further, the IRS recommends organizations that receive the scams or fall victim to same to file a complaint with the Internet Crime Complaint Center (IC3,) operated by the Federal Bureau of Investigation.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
How to Dissolve a Corporation in New Jersey: A Step-by-Step Guide post image

How to Dissolve a Corporation in New Jersey: A Step-by-Step Guide

Closing your business can be a difficult and challenging task. For corporations, the process includes formal approval of the dissolution, winding up operations, resolving tax liabilities, and filing all required paperwork. Whether you need to understand how to dissolve a corporation in New York or New Jersey, it’s imperative to take all of the proper […]

Author: Christopher D. Warren

Link to post with title - "How to Dissolve a Corporation in New Jersey: A Step-by-Step Guide"
Gross Lease vs. Net Lease: Understanding the Key Differences post image

Gross Lease vs. Net Lease: Understanding the Key Differences

Commercial leases can take a variety of forms, which is often confusing for both landlords and tenants. Understanding the different types, especially the gross lease structure, is important when selecting the lease that best suits your needs. One key distinction between lease types is how rent is calculated and paid. This article addresses the two […]

Author: Robert L. Baker, Jr.

Link to post with title - "Gross Lease vs. Net Lease: Understanding the Key Differences"
What to Do If You Are Impacted by a Retailer Bankruptcy Part 2 post image

What to Do If You Are Impacted by a Retailer Bankruptcy Part 2

Over the past year, brick-and-mortar stores have closed their doors at a record pace. Fluctuating consumer preferences, the rise of online shopping platforms, and ongoing economic uncertainty continue to put pressure on the retail industry. When a retailer seeks bankruptcy protection, a myriad of other businesses are often impacted. Whether you are a supplier, customer, […]

Author: Brian D. Spector

Link to post with title - "What to Do If You Are Impacted by a Retailer Bankruptcy Part 2"
The Current Administration's Proposals for the Financial Services and Banking Industries Will Affect Your Business post image

The Current Administration's Proposals for the Financial Services and Banking Industries Will Affect Your Business

Since his inauguration two months ago, Donald Trump’s administration and the Congress it controls have indicated important upcoming policy changes. These changes will impact financial services policies and priorities. The changes will particularly affect cryptocurrency, as well as banking rules and regulations. Key Regulatory Changes in Cryptocurrency For example, in the burgeoning cryptocurrency business environment, […]

Author: Dan Brecher

Link to post with title - "The Current Administration's Proposals for the Financial Services and Banking Industries Will Affect Your Business"
Tips for Commercial Landlords Impacted by Wave of Retailer Bankruptcies Part 1 post image

Tips for Commercial Landlords Impacted by Wave of Retailer Bankruptcies Part 1

The retail sector has experienced a wave of bankruptcy filings over the last year. Brick-and-mortar businesses in financial distress include big-name brands like Big Lots, Party City, The Container Store, and Vitamin Shoppe. When large retailers seek bankruptcy protection, they are not the only businesses impacted. Landlords can be particularly hard hit. While commercial landlords […]

Author: Brian D. Spector

Link to post with title - "Tips for Commercial Landlords Impacted by Wave of Retailer Bankruptcies Part 1"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!

Please select a category(s) below: