Thousands of taxpayers affected by W-2 Phishing attacks this year

  • 1 Replies

Offline Bugbatter

  • Microsoft® MVP
  • Administrator
  • Diamond Member
  • 10671

Criminals show no signs of slowing when it comes to targeting W-2 information

Thousands of taxpayers have been impacted by a wave of Phishing attacks targeting W-2 records, with more than sixty organizations reporting such incidents in the first half of the year.

By taking advantage of the trust relationships that exist within a given company; these attacks have resulted in at least $2.3 billion in losses over the last three years.

Business Email Compromise / Correspondence attacks (BEC attacks) aren't overly clever, but they're effective. A person with authority is impersonated, and a lower-level staffer is asked to share W-2 records or related payroll information. That's all there is to it.

Microsoft MVP Consumer Security 2006-2016
Microsoft Windows Insider MVP 2016-


Offline Grumpy Old Man

  • Bronze Member
  • 18
Re: Thousands of taxpayers affected by W-2 Phishing attacks this year
« Reply #1 on: September 05, 2016, 06:05:07 PM »
The impact was huge! I work ID Theft 2 days per week for the IRS; our heuristics are getting better but when the fraudsters know the employment data, it gets complicated. The fraudsters can now call in looking for "their" refund so we have upgraded our verification processes. I have had people say "No one asked me these questions the last time I called", then there is a pause, disconnect - next call.