{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-seagate-ceo-impersonation-phish-exposes-every-us-employee-s-w-2"},"incident":{"title":"Seagate CEO-impersonation phish exposes every US employee's W-2","date":"2016-03-01","date_precision":"day","victim_org":"Seagate Technology","sector":"Technology","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No direct wire loss; downstream harm was tax refund fraud exposure for employees.","records_affected":null,"threat_actor":null,"summary":"On 1 March 2016 a Seagate employee responded to a phishing email spoofing a request from the CEO and sent the 2015 W-2 tax forms for all current and former US-based employees to an unauthorized recipient. Seagate described the number affected as several thousand but well under 10,000, and offered two years of credit monitoring. Seagate's CFO called the incident a result of human error and a lack of vigilance.","how_it_worked":"The attacker spoofed the display name and writing style of a senior executive and emailed payroll or HR staff during tax season with a short, direct request for the complete W-2 file. Two levers combined: the authority of a named chief executive and the seasonal normality of the request, since W-2 handling is exactly what payroll does in early March. The employee attached the full file and replied. Because W-2s pair Social Security numbers with income and address data, the single reply produced everything needed to file fraudulent tax refunds in each employee's name.","lessons":"Bulk employee tax or PII files should never be releasable by email reply; a workflow requiring release through an authenticated HR system with a second approver would have blocked it.","confidence":"Confirmed","sources":[{"title":"Seagate Phish Exposes All Employee W-2's","url":"https://krebsonsecurity.com/2016/03/seagate-phish-exposes-all-employee-w-2s/","publisher":"Krebs on Security"},{"title":"Snapchat and Seagate fall prey to new W-2 scam","url":"https://www.cbsnews.com/news/snapchat-and-seagate-fall-prey-to-new-w-2-scam/","publisher":"CBS News"}],"entry_type":"incident","slug":"2016-seagate-ceo-impersonation-phish-exposes-every-us-employee-s-w-2","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-seagate-ceo-impersonation-phish-exposes-every-us-employee-s-w-2"}}