W-2 phishing is a fraud scheme in which an attacker impersonates a company executive and asks HR or payroll to send copies of employee W-2 forms. It is seasonal, it is highly effective, and unlike most payroll fraud it does not steal money from the employer. It steals the workforce's tax identities.
The request usually arrives from someone appearing to be the CEO or CFO, is brief, and asks for a list of all employee W-2s or a summary file "for review." An employee who complies has just transmitted every worker's name, address, Social Security number, and annual wages in a single file.
Three factors combine. The request comes from apparent authority, so questioning it feels risky. It arrives during tax season, when requests for wage data are genuinely routine. And it asks for something the recipient can produce in minutes, so there is no natural pause for reflection.
The attacker also does not need to breach anything. There is no malware, no exploited vulnerability, nothing for a security tool to detect. The entire attack is an email and a plausible pretext, which is why technical defenses catch so little of it.
Stolen W-2 data is used to file fraudulent tax returns and claim refunds before the real employee files. Employees typically discover the fraud when their legitimate return is rejected as a duplicate, often months later, and then face a lengthy process to resolve it with tax authorities.
For the employer, the consequences arrive on several fronts at once. Breach notification obligations are triggered, since Social Security numbers are involved. Affected employees generally must be offered credit monitoring. And the employer faces a workforce that has been directly harmed by an HR failure, which does lasting damage regardless of how the legal exposure resolves.
These campaigns concentrate between January and April, peaking in the weeks around when W-2s are issued. Attackers time requests to coincide with when the data genuinely exists and when payroll staff genuinely are handling it.
A secondary wave targets organizations after a publicized layoff, acquisition, or leadership change, when internal processes are disrupted and staff are less certain about who is authorized to ask for what. Any period of organizational upheaval warrants extra caution on bulk data requests.
Bulk employee data should never be transmitted on the strength of an email request alone, regardless of who appears to have sent it. Verification through a separate channel — a phone call to a number already on file, or an in-person confirmation — defeats the attack entirely, including the version where the executive's actual account has been compromised.
Supporting controls that matter:
Speed changes outcomes. Reporting the incident to tax authorities promptly can allow protective flags on affected accounts before fraudulent returns are filed. Employees need to be told quickly and specifically, so they can take their own protective steps rather than learning about it when a return is rejected.
Breach notification requirements vary by state and are time-bound, and California imposes its own obligations where residents are affected. An employer discovering this exposure should treat the notification analysis as urgent rather than something to work through after the operational response.
W-2 phishing sits alongside payroll diversion and payroll impersonation as variations on the same weakness: payroll processes that accept email as sufficient authorization. Employers that establish out-of-band verification as a standing rule tend to close all three at once.
Employer's Guardian helps employers build these verification practices into payroll operations through payroll services, covering data handling, request authorization, and seasonal readiness.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.