Be on the Watch for W-2 Phishing Scams!

Stu Sjouwerman | Feb 19, 2021

Tax SeasonWith tax season just around the corner, this simple, yet effective social engineering theme is perfect to get users to respond to phishing attacks exactly the way the bad guys want.

Every successful phishing attack starts with the premise of creating an email that will be sufficient to get the emotional buy-in from the reader enough to get them to interact. This has been shown to be something either positive or negative – doesn’t make much difference, as long as it gets the recipient to click the link, open the attachment, reply, etc.

W-2s have already begun to be delivered to employees – some the old-fashioned way via mail, and most via email as an invitation to download the PDF version. Scammers know this and can easily impersonate your organization’s HR department asking the employee to review and/or download their W-2, offering up either a malicious attachment or link that will be used to infect the recipient’s endpoint, attempt to capture their logon credentials to Office 365, etc.

It’s important for you to educate your users on phishing scams like this. One click can spell the difference between going about your day or having most of the organization at a halt due to a ransomware attack or data breach. Enrolling users in new school Security Awareness Training is an effective means to educate users and validate their ability to spot a phishing attack before it does damage.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.