The Ohio Department of Taxation (ODT) is echoing phishing scam alerts made by the IRS earlier this month in an effort to protect businesses and employees state-wide from identity theft and tax fraud.
According to ODT, payroll and human resources offices at companies nationwide – including some in Ohio – reportedly received emailed requests that appear to be sent from a high ranking member of the company’s management team requesting confidential payroll data. While the emails appear to be legitimate, they are actually being sent by cybercriminals who are looking to fool employees into sending them detailed payroll and W-2 information. The imposters then use the information to file fraudulent tax returns.
“The scam has worked on more than 30 companies resulting in the theft of W-2 tax information for thousands of current and former employees,” ODT’s news release states. “The W-2 form contains an employee’s Social Security number, salary and other confidential data. This information enables thieves to create a realistic looking, but fraudulent tax return requesting a tax refund that is then filed with Ohio or other states, and the IRS.”
The frequency of tax fraud and identity theft continues to increase at an alarming rate. This tax season alone, the IRS reported an approximate 400 percent increase in phishing and malware incidents – a surge that was addressed back in February.
“If your CEO appears to be emailing you for a list of company employees, check it out before you respond,” said IRS Commissioner John Koskinen. “Everybody has a responsibility to remain diligent about confirming the identity of people requesting personal information about employees.”
You can take a proactive stance when it comes to protecting your company from these scams by encouraging your employees to pay close attention to emails that request sensitive information, such as the names of employees, Social Security numbers, dates of birth, addresses and/or salary information or copies of employee’s W-2 information. You can also let them know that they should never send sensitive information until a conversation takes place, either in-person or over the phone, with the member of management seeking the information. You can also check out the information provided here for general insight from ODT that could be used to help your employees identify phishing attempts and email scams.
If your Ohio business has been the victim of or experienced this or any other type of email phishing scheme, contact ODT immediately at 800.282.1780 to protect against potential tax fraud and safeguard Ohio taxpayer dollars.
Those who are interested in learning more about the increasing threat of cybercrime should check out The Columbus Cybersecurity Series. Presentations are scheduled to take place throughout the year and will focus on ways to help business owners learn more about cyber threats. The first installment is scheduled for Wednesday, April 6. The event is free but registration is required to attend. Attendees will walk away with new insight into these attacks as well as tips and advice that will help you protect your business.
By Lisa Beamer, CPA (New Philadelphia office)