Snapchat, Seagate Amongst Firms Duped in Tax-Fraud Phishing Scam

Advertisement
By Associated Press | Updated: 9 March 2016 15:20 IST
Tax-filing season is turning into a nightmare for thousands of employees whose companies have been duped by email fraudsters. A major phishing scheme has tricked several major companies - among them, the messaging service Snapchat and disk-drive maker Seagate Technology - into relinquishing tax documents that exposed their workers' incomes, addresses and Social Security numbers.

The scam, which involved fake emails purportedly sent by top company officials, convinced the companies involved to send out W-2 tax forms that are ideal for identity theft. For instance, W-2 data can easily be used to file bogus tax returns and claim fraudulent refunds.

The embarrassing breakdowns have prompted employers to apologize and offer free credit monitoring to employees. Such measures, however, won't necessarily shield unwitting victims from the headaches that typically follow identity theft.

"This mistake was caused by human error and lack of vigilance, and could have been prevented," Seagate's chief financial officer, Dave Morton, wrote in a March 4 email to the company's employees about the breach.

Advertisement

The swindlers behind the tax scam are exploiting human gullibility rather than weaknesses in computer or Internet security. They have targeted company payroll and personnel departments, in many instances with emails claiming to be requests from the company CEO asking for copies of worker W-2s.

Advertisement

The schemes are so widespread that the IRS sent a March 1 notice alerting employers' payroll departments of the spoofing emails. The agency said the scheme has so far claimed "several victims," but declined Tuesday to disclose how many other employers had reported releasing W-2s to unauthorized parties. The IRS said it's seen a 400 percent increase in phishing and computer malware incidents this tax-filing season.

The federal alert didn't come soon enough for Snapchat, which on Feb. 28 revealed that its payroll department had been duped by an email impersonating its CEO, Evan Spiegel. The Los Angeles company didn't specify how many employee W-2s it released. Snapchat didn't respond to requests for comment Tuesday.

Advertisement

"When something like this happens, all you can do is own up to your mistake, take care of the people affected, and learn from what went wrong," Snapchat wrote in a post on its corporate blog .

Seagate acknowledged surrendering the W-2s for all of its current and former employees who worked at the company last year. The Cupertino, California, company said "several thousand" people were affected, but declined to be more precise. As of July last year, Seagate employed about 52,000 workers but all but 10,500 of them were based in Asia.

Advertisement

Both Snapchat and Seagate notified federal authorities about the phishing attacks and are offering affected workers two years of free credit monitoring.

It's unclear how many other employers have been sucked into the tax scam. Hundreds of companies appear to have been targeted, according to Stu Sjouwerman, CEO of KnowBe4, a Florida company that trains employers to detect and avoid such scams.

Phishing attacks commonly occur during holidays and other annual events, such as tax season, to prey upon people's routines, said Farih Orhan, director of technology at security firm Comodo. The attacks are becoming increasingly effective because they rely on powers of persuasion instead of an attachment or link that might raise suspicion, said Ed Jennings, chief operating officer at email security company Mimecast.

"It's just like someone who convinces you to hand over $20 on the street," Jennings said.

Sjouwerman said the W-2 seeking attacks are most likely are being sent by Eastern European hacker groups planning to sell the information or claim fraudulent tax refunds.

The most effective phishing attacks use emails decked in company logos and colors to reduce the chances of detection, Orhan said. It's relatively easy for con artists to pose as a CEO online, since they can quickly fetch convincing details from a Google search or a perusal of professional networking service LinkedIn.

That doesn't excuse payroll or personnel departments who reflexively acquiesce to requests in apparently legitimate email, experts say. For instance, Sjouwerman said his firm's controller received a phishing email that, at first glance, appeared to be sent by him. But the email asked the controller to "kindly prepare" employees' W-2s, a phrase that he never uses. Company employees were alert enough not to send out the W-2s.

Even without a red flag like that, payroll and personnel specialists should be trained well enough to question why a CEO needs to see individual worker W-2s in the first place.

"It's a case of: 'Oh, the boss wants it'," Sjouwerman said. "They stop thinking, 'Why would this be?'"

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apps, Internet, Laptops, PC, Seagate, Snapchat
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: Thamma, Mrs Deshpande, Raat Akeli Hai The Bansal Murders, and More
  2. Here's When the Realme 16 Pro Series Will Launch in India
  3. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  4. Instagram Will Now Restrict the Number of Hashtags You Can Use
  5. Samsung Announces Exynos 2600 as World's First 2nm Chipset
  6. Oppo Reno 15 Pro Mini Tipped to Launch as First Compact Reno Smartphone
  7. Google's Pixel Upgrade Program Lets You Get the Latest Model Every Year
  8. Nvidia's GeForce RTX 50 Series GPUs Are About to Be Scarce
  9. Google Will Now Let You Check AI-Generated Videos Directly in Gemini
  10. Meta's New AI Models Could Challenge Google, OpenAI in Image and Video Generation
  1. Vivo X200T Key Specifications Tipped Ahead of India Launch; Could Feature Three 50-Megapixel Cameras
  2. Meta Reportedly Building Three New Generative AI Models With Focus on Image and Video Generation
  3. Google Pixel Upgrade Program Launched in India With Assured Buyback of Pixel 10 Series Models
  4. Intergalactic: The Heretic Prophet Targeting Mid-2027 Launch as Naughty Dog Orders Overtime: Report
  5. Apple's Foldable iPhone Shipments May Slip to 2027 Despite 2026 Launch, Analyst Says
  6. Realme 16 Pro Series India Launch Date Announced: See Expected Specifications, Features
  7. Google Brings SynthID-Powered Deepfake AI Video Detection Tool to Gemini App
  8. Dreame E1 Phone to Reportedly Debut With 108-Megapixel Camera and 5,000mAh Battery: Expected Specifications
  9. Oppo Pad Air 5 Launch Date, Colourways, Storage Options Revealed: See Expected Specifications, Features
  10. Raju Weds Rambai Now Streaming Online: What You Need to Know
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.