What happened
In late March 2016 an employee in the payroll department of the US grocery chain Sprouts Farmers Market responded to an email that appeared to come from a company executive and attached the W-2 tax forms of approximately 21,000 employees. The forms contained names, addresses, Social Security numbers and wage data. Class-action litigation followed within weeks.
How the deception worked
The attacker sent a short, plain email to a payroll staff member that appeared to come from a Sprouts executive and asked for all employee W-2 forms. The pretext matched the calendar: late March is the height of US tax season, when internal requests for wage data are entirely routine, so the ask raised no category alarm. The message used seniority as the trust signal and gave no reason for the request, which in a large organisation reads as normal executive brevity rather than suspicious. The employee replied with the file, handing over a complete identity-theft package for the workforce.
The control that would have caught it· our reading, not a claim from the sources
Bulk employee tax or payroll data should only leave through a ticketed request in an HR system, never as an email attachment, regardless of who appears to be asking.
Sources (2)
- Employers Beware of Phishing ScamsThe National Law Review·natlawreview.comOpen ↗
- Sprouts Farmers Market Class Actions Target W-2 Phishing ScamTop Class Actions·topclassactions.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.