LLP_News_Alert_NEW_BRANDING


UHY LLP Michigan Practice
This_Just_In
QUICK LINKS
ARCHIVE
Missed an issue? New subscriber? Visit our news archive.

Join Our Mailing List
IRS WARNS OF DAMAGING W2 PHISHING EMAIL SCAMMain
IRS warns a damaging W-2 phishing email scam is spreading aggressively beyond corporate America.

** Companies are urged to alert their payroll, HR and finance employees to guard against the scam **

Two weeks ago the IRS issued a warning about a W-2 phishing email scam. Less than a week later the IRS issued an urgent alert stressing the scam is spreading aggressively beyond corporate America and into schools, hospitals, nonprofits, middle market companies, etc.

What is it?
Rather than going after W-2 data on an individual by individual basis, hackers have shifted their focus to a much more damaging target - mass data thefts. The W-2 phishing email scam works like this: criminals use spoofing techniques to disguise an email to make it appear as if it is coming from a company executive (CEO, President) and it is sent to payroll or HR employees requesting employee W-2 data. Cybercriminals specifically target less experienced employees working with sensitive data by researching company employees via LinkedIn or other sites. Unfortunately these less experienced employees will often create a zip file of all W-2s and attach it to a reply email, thus exposing all of the company's employees to identity theft.

Here are some examples of language used in the emails to request the W-2 data:
  • "Kindly send me the individual 2016 W2 (PDF) and earnings summary of all W2 of our company staff for a quick review."
  • "Can you send me the updated list of employees with full details (Name, Social Security Number, Date of Birth, Home Address, Salary)"
  • "I want you to send me the list of W2 copy of employees wage and tax statement for 2016, I need them in PDF file type, you can send it as an attachment. Kindly prepare the lists and email them to me ASAP." 
Why is the W-2 phishing scam so harmful?
Cybercriminals will use the information obtained in these thefts to file fraudulent tax returns seeking refunds. In the case of larger organizations, the number of employees impacted will be in the thousands or beyond. Unfortunately in many cases the theft is not recognized until employees who are victims of the scam have their tax returns rejected by the IRS as a duplicate filing.

What can you do?
  1. Make sure your company's payroll, HR and finance employees are aware they likely will be targeted by this scam. These employees need to be on high alert.
  2. Implement procedures that prohibit the emailing of any sensitive employee data (e.g., W-2s, social security numbers) and restrict the ability to initiate and process wire transfers.
  3. Forward this alert to any contacts you have at nonprofit organizations, schools districts, middle market companies, etc. to warn them to the dangers of this W-2 scam. 
UHY Advisors can help develop the training and awareness programs you need to avoid falling victim to these types of scams. Contact your professional in Detroit 313 964 1040, Farmington Hills 248 355 0280 or Sterling Heights 586 254 8141, or visit us the web at www.uhy-us.com.

Back to top
 
  
EVENTS CALENDAR

2/16 UHY CARES TENTH ANNUAL D.M.G.C. TEXAS HOLD 'EM TOURNAMENT
We hope you can once again join us for a fun night of cards and networking for a great cause! This year's charity poker tournament will be held on Thursday, February 16 at The Iroquois Club. Registration is at 6. Game starts promptly at 7. $100 buy-in and $50 re-buy. Contact Jessica Labut to save your spot! Cash, check or credit card contributions accepted in advance or at the door. Sponsorship opportunities available. UHY Cares in cooperation with UHY LLP, the D.M.G.C. and the McCarty family hope to see you there!

3/9 UHY LLP Nonprofit Cybersecurity Workshop
The "human firewall" is now more important than ever for effective cybersecurity. Technology is no longer enough. Phishing, vishing and email compromise are billion dollar threats to businesses of all sizes. Learn how to strengthen your organization's human firewall and why cybersecurity is important for nonprofits at the UofM Detroit Center on Thursday, March 19 from 8:30-10:30AM. Two hours of A&A CPE (qualifies for Yellow Book credit) is available. Pre-registration for this complimentary breakfast program is required. To RSVP contact Jessica Labut.

Back to top


Our firm provides the information in this newsletter as tax information and general business or economic information or analysis for educational purposes, and none of the information contained herein is intended to serve as a solicitation of any service or product. This information does not constitute the provision of legal advice, tax advice, accounting services, investment advice, or professional consulting of any kind. The information provided herein should not be used as a substitute for consultation with professional tax, accounting, legal, or other competent advisors. Before making any decision or taking any action, you should consult a professional advisor who has been provided with all pertinent facts relevant to your particular situation. Tax articles in this newsletter are not intended to be used, and cannot be used by any taxpayer, for the purpose of avoiding accuracy-related penalties that may be imposed on the taxpayer. The information is provided "as is," with no assurance or guarantee of completeness, accuracy, or timeliness of the information, and without warranty of any kind, express or implied, including but not limited to warranties of performance, merchantability, and fitness for a particular purpose. 

UHY Advisors, Inc. provides tax and business consulting services through wholly owned subsidiary entities that operate under the name of "UHY Advisors." UHY Advisors, Inc. and its subsidiary entities are not licensed CPA firms. UHY LLP is a licensed independent CPA firm that performs attest services in an alternative practice structure with UHY Advisors, Inc. and its subsidiary entities. UHY Advisors, Inc. and UHY LLP are U.S. members of Urbach Hacker Young International Limited, a UK company, and form part of the international UHY network of legally independent accounting and consulting firms. "UHY" is the brand name for the UHY international network. Any services described herein are provided by UHY Advisors and/or UHY LLP (as the case may be) and not by UHY or any other member firm of UHY. Neither UHY nor any member of UHY has any liability for services provided by other members.

Published by UHY LLP News. 
Copyright © 2017 UHY LLP. All rights reserved.