What happened
In news release IR-2017-20, issued 2 February 2017, the IRS warned that the W-2 spear phishing scam had spread well beyond corporations to school districts, tribal organizations and casinos, nonprofits, chain restaurants, temporary staffing agencies, healthcare providers and shipping and freight companies. The agency also flagged an evolved variant that follows the W-2 theft with a fraudulent wire transfer request.
How the deception worked
Criminals spoofed an organisation's executive and emailed payroll or human resources staff asking for a list of all employees and their Forms W-2. School districts and small nonprofits were attractive because payroll is often handled by one or two people with no formal verification procedure and no security team. After the W-2 file was sent, the same spoofed executive followed up with a request to the payroll or comptroller staff to wire funds to a specified account, exploiting the compliance momentum created by the first successful request. Some organisations lost both the employee data and the money.
AI involvement · No AI reported
No AI involvement reported in the IRS alert.
The control that would have caught it· our reading, not a claim from the sources
Small public-sector and nonprofit payroll functions need a written, mandatory callback rule for executive requests, since they lack the compensating controls larger firms rely on.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.