Be on the Watch for W-2 Phishing Scams!

Tax SeasonWith tax season just around the corner, this simple, yet effective social engineering theme is perfect to get users to respond to phishing attacks exactly the way the bad guys want.

Every successful phishing attack starts with the premise of creating an email that will be sufficient to get the emotional buy-in from the reader enough to get them to interact. This has been shown to be something either positive or negative – doesn’t make much difference, as long as it gets the recipient to click the link, open the attachment, reply, etc.

W-2s have already begun to be delivered to employees – some the old-fashioned way via mail, and most via email as an invitation to download the PDF version. Scammers know this and can easily impersonate your organization’s HR department asking the employee to review and/or download their W-2, offering up either a malicious attachment or link that will be used to infect the recipient’s endpoint, attempt to capture their logon credentials to Office 365, etc.

It’s important for you to educate your users on phishing scams like this. One click can spell the difference between going about your day or having most of the organization at a halt due to a ransomware attack or data breach. Enrolling users in new school Security Awareness Training is an effective means to educate users and validate their ability to spot a phishing attack before it does damage.

Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

Subscribe to Our Blog

Comprehensive Anti-Phishing Guide

Get the latest about social engineering

Subscribe to CyberheistNews