Back to blog
1 min readBy ACWI

W-2 Phishing Is Still a Threat

This is a good time of year to remind employees to take precautions against W-2 phishing scams. Hackers obtain employee W-2 Forms for filing fraudulent tax returns that seek big refunds. These phishing emails arrive typically around the time firms have…

This is a good time of year to remind employees to take precautions against W-2 phishing scams.

Hackers obtain employee W-2 Forms for filing fraudulent tax returns that seek big refunds. These phishing emails arrive typically around the time firms have issued W-2s to their employees.

“A W-2 email phishing scam can have a devastating impact on a business and its employees,” warn attorneys Mary Costigan and Joseph J. Lazzarotti of the Jackson Lewis law firm.

The way the scam works: An email message is sent to an HR or accounting department employee, presumably from a higher-up. Both the “To” and “From” email addresses are legitimate internal addresses, as are the sender and recipient names.

The fake email asks the employee to forward the company’s W-2 forms, or related tax data, to the sender. This request aligns with the job responsibilities of both the employee and the supposed internal sender.

The employee relies on the accuracy of the sender email address, coupled with the sender’s job title and role, and forwards the confidential W-2 information. The information actually ends up going to the criminal’s hidden email address.

“If successful, the cyber-criminal obtains a trove of sensitive employee data that can include names, addresses, salary information, social security numbers, as well as employer information needed for tax filings,” the attorneys explain.

The information is used to file fake individual tax returns to generate fraudulent tax refunds, or it’s sold on the Dark Web to identity thieves.

The attorneys remind employers that experts say the best defense is employee awareness. This includes ongoing security awareness training for all levels of employees, simulated phishing exercises, internal procedures for verifying transfers of sensitive information, and reducing the posting of personal information online.

Originally published March 2, 2021 · updated June 23, 2025.

Tags:2-phishing-scamsemployee-awarenessfraudulent-tax-returnssecurity-awareness-trainingw

Related reading

Browse all posts →
1 min

ACWI: Warehousing for Mid-Tier Companies

https://vimeo.com/1165350849?fl=pl&fe=sh Conversations at Manifest 2026: American Chain of Warehouses President Chris Kane was recently featured in a discussion with Russell W. Goodman , Contributing Editor at SupplyChainBrain, highlighting the evolving role…

11 min

Get to Know Our Member Companies: The Backbone of ACWI

At American Chain of Warehouses (ACWI), our strength lies in the diversity and expertise of our member companies. Each member brings unique capabilities and specialized services to our network, creating a dynamic community that drives innovation and…