Tax Form Fraud: What Employers Need to Know
August 18, 2026
Tax form fraud covers schemes involving employment tax documents — obtaining W-2 or 1099 data to file fraudulent returns, manipulating withholding elections, or issuing fraudulent forms. For employers it is concentrated in a predictable season and aimed at a predictable function, which makes it one of the more preventable fraud categories.
The distinguishing feature is that the employer is usually not the direct financial victim. The workforce is. That changes the response calculus considerably.
Obtaining the data
The dominant scheme is a request to HR or payroll, apparently from an executive, asking for employee W-2 copies or a summary file. An employee who complies transmits every worker's name, address, Social Security number, and annual wages in one file.
The stolen data is used to file fraudulent returns claiming refunds before the real employees file. Employees typically discover this months later when their legitimate return is rejected as a duplicate, and then face a lengthy process to resolve it.
A quieter variant targets the self-service portal. An attacker with an employee's credentials downloads their W-2 directly — no request to HR, nothing for anyone to notice, and no indication anything happened until the fraudulent return is filed.
Manipulating withholding
A second category involves altering an employee's withholding elections, typically to claim exemption so that no federal tax is withheld and net pay increases. This is sometimes external fraud and sometimes an employee acting on bad advice.
The consequence lands on the employee at filing time, in the form of a substantial unexpected liability. But it also creates employer exposure, because employers have obligations regarding withholding and are expected to act on properly submitted elections rather than implausible ones processed without review.
Withholding changes are worth including in the pre-payroll change review for the same reason banking changes are — a sudden exemption claim from an employee who has always had standard withholding warrants a confirmation.
Fraudulent form issuance
A third pattern involves forms issued to people who did not earn the reported income, generally as part of a broader scheme — laundering payments, generating deductions, or supporting fraudulent credit applications. Where an employer's systems or identity are used for this, the exposure includes both the tax consequences and the harm to individuals who receive forms reporting income they never earned.
This is where reconciliation of payroll records against actual employees matters. A ghost employee on payroll produces a real tax form.
The seasonal pattern
These campaigns concentrate between January and April, peaking around when W-2s are issued. Attackers time requests to coincide with when the data genuinely exists and payroll staff are genuinely handling it, so the request fits the moment.
A secondary wave follows organizational disruption — layoffs, acquisitions, leadership changes — when internal processes are unsettled and staff are less certain who is authorized to request what.
The practical implication is that a brief reminder to payroll and HR staff each January, ahead of the season, is disproportionately effective relative to its cost.
Controls
- Out-of-band verification for any bulk employee data request, regardless of apparent sender. This single control defeats the primary scheme, including when an executive's actual account has been compromised.
- A defined channel for wage data requests, so anything arriving outside it is visibly abnormal.
- Multi-factor authentication on self-service portals, which addresses the credential-based variant.
- Notification when tax documents are downloaded or withholding elections change.
- Withholding changes included in pre-run change review.
- Restricted bulk export of tax documents, with logging.
- Seasonal reinforcement for payroll and HR staff each January.
Leadership stating explicitly that verification applies to requests from them, and that no one will face consequences for verifying, is what makes the first control hold under pressure. Without it, the policy is abandoned the first time a request appears to come from the CFO on a deadline.
Responding to exposure
Speed materially changes outcomes. Reporting promptly to tax authorities can allow protective flags on affected accounts before fraudulent returns are filed. Employees need to be told quickly and specifically so they can take their own protective steps rather than discovering the problem when a return is rejected.
Breach notification obligations are triggered where Social Security numbers are involved, vary by state, and are time-bound. California imposes its own requirements where residents are affected. An employer discovering this exposure should treat the notification analysis as urgent, in parallel with the operational response rather than after it.
Credit monitoring is generally offered where identifiers were exposed. The workforce reaction also warrants preparation — employees learning their identifiers were exposed through an HR process respond differently than customers do, because they had no choice about providing the data.
Employer's Guardian helps employers establish request verification and data handling practices across payroll operations through payroll services.
This article provides general educational information, not legal or tax advice. Requirements vary by jurisdiction. Consult qualified counsel or a tax professional regarding specific obligations.

