What happened
On 1 March 2016 a Seagate employee responded to a phishing email spoofing a request from the CEO and sent the 2015 W-2 tax forms for all current and former US-based employees to an unauthorized recipient. Seagate described the number affected as several thousand but well under 10,000, and offered two years of credit monitoring. Seagate's CFO called the incident a result of human error and a lack of vigilance.
How the deception worked
The attacker spoofed the display name and writing style of a senior executive and emailed payroll or HR staff during tax season with a short, direct request for the complete W-2 file. Two levers combined: the authority of a named chief executive and the seasonal normality of the request, since W-2 handling is exactly what payroll does in early March. The employee attached the full file and replied. Because W-2s pair Social Security numbers with income and address data, the single reply produced everything needed to file fraudulent tax refunds in each employee's name.
AI involvement · No AI reported
No AI involvement reported.
The control that would have caught it· our reading, not a claim from the sources
Bulk employee tax or PII files should never be releasable by email reply; a workflow requiring release through an authenticated HR system with a second approver would have blocked it.
Sources (2)
- Seagate Phish Exposes All Employee W-2'sKrebs on Security·krebsonsecurity.comOpen ↗
- Snapchat and Seagate fall prey to new W-2 scamCBS News·cbsnews.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.