W-2 phishing is a fraud scheme in which an attacker impersonates a company executive and asks HR or payroll to send copies of employee W-2 forms. It is seasonal, it is highly effective, and unlike most payroll fraud it does not steal money from the employer. It steals the workforce's tax identities.

The request usually arrives from someone appearing to be the CEO or CFO, is brief, and asks for a list of all employee W-2s or a summary file "for review." An employee who complies has just transmitted every worker's name, address, Social Security number, and annual wages in a single file.

Why this scheme works so reliably

Three factors combine. The request comes from apparent authority, so questioning it feels risky. It arrives during tax season, when requests for wage data are genuinely routine. And it asks for something the recipient can produce in minutes, so there is no natural pause for reflection.

The attacker also does not need to breach anything. There is no malware, no exploited vulnerability, nothing for a security tool to detect. The entire attack is an email and a plausible pretext, which is why technical defenses catch so little of it.

What happens to the data

Stolen W-2 data is used to file fraudulent tax returns and claim refunds before the real employee files. Employees typically discover the fraud when their legitimate return is rejected as a duplicate, often months later, and then face a lengthy process to resolve it with tax authorities.

For the employer, the consequences arrive on several fronts at once. Breach notification obligations are triggered, since Social Security numbers are involved. Affected employees generally must be offered credit monitoring. And the employer faces a workforce that has been directly harmed by an HR failure, which does lasting damage regardless of how the legal exposure resolves.

The timing pattern

These campaigns concentrate between January and April, peaking in the weeks around when W-2s are issued. Attackers time requests to coincide with when the data genuinely exists and when payroll staff genuinely are handling it.

A secondary wave targets organizations after a publicized layoff, acquisition, or leadership change, when internal processes are disrupted and staff are less certain about who is authorized to ask for what. Any period of organizational upheaval warrants extra caution on bulk data requests.

Recognizing the request

  • An executive asking directly for employee data rather than going through normal reporting channels
  • Reply-to address that differs from the display name, or a domain off by a character
  • Requests for data "in a single file" or "all employees" rather than a specific, scoped need
  • Language emphasizing confidentiality or asking the recipient not to discuss the request
  • Pressure framed around a deadline, a board meeting, or an auditor
  • An executive who has never previously made such a request doing so for the first time
  • Arrival outside business hours, or while the named executive is known to be traveling

The control that ends the scheme

Bulk employee data should never be transmitted on the strength of an email request alone, regardless of who appears to have sent it. Verification through a separate channel — a phone call to a number already on file, or an in-person confirmation — defeats the attack entirely, including the version where the executive's actual account has been compromised.

Supporting controls that matter:

  • A standing rule with no exceptions. Staff need to know that verification is mandatory and that no executive will ever be annoyed by it. Leadership stating this explicitly removes the social pressure the attack depends on.
  • A defined channel for wage data requests. Legitimate needs should route through a known process, so anything arriving outside it is visibly abnormal.
  • Encryption and access limits. Bulk W-2 files should not be casually exportable or sittable in an inbox.
  • Seasonal reinforcement. A short reminder to payroll and HR staff each January, when the campaigns start.
  • A rehearsed response. Knowing in advance who to contact if data has already been sent, because the first hours matter.

If it has already happened

Speed changes outcomes. Reporting the incident to tax authorities promptly can allow protective flags on affected accounts before fraudulent returns are filed. Employees need to be told quickly and specifically, so they can take their own protective steps rather than learning about it when a return is rejected.

Breach notification requirements vary by state and are time-bound, and California imposes its own obligations where residents are affected. An employer discovering this exposure should treat the notification analysis as urgent rather than something to work through after the operational response.

Where it fits

W-2 phishing sits alongside payroll diversion and payroll impersonation as variations on the same weakness: payroll processes that accept email as sufficient authorization. Employers that establish out-of-band verification as a standing rule tend to close all three at once.

Employer's Guardian helps employers build these verification practices into payroll operations through payroll services, covering data handling, request authorization, and seasonal readiness.

This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.

Let's Talk! Schedule a Conversation

For additional information, pricing, and/or free consultation, contact us. We'd be happy to discuss your situation.

Contact Us Today!

Want a professional to walk you through your HR needs shopping list?

At Employer’s Guardian, our experts are here to help. We are happy to work with you to understand your HR needs. Get in touch—give us a call or fill out our online contact form and we’ll promptly get back to you!

Contact Us Today!