W-2 Phishing, Wire Transfer Scam Targets School Districts

The Internal Tax Revenue Service (IRS) earlier this month issued an urgent alert to all employers that an extensive W-2 e-mail phishing scam has permeated the corporate sector and spread to school districts, nonprofits and others.  

“This is one of the most dangerous email phishing scams we’ve seen in a long time. It can result in the large-scale theft of sensitive data that criminals can use to commit various crimes, including filing fraudulent tax returns,” IRS Commissioner John Koskinen said in the alert. “We need everyone’s help to turn the tide against this scheme.”

How the scam works: Cyber criminals use spoofing techniques to disguise an e-mail to make it look like it comes from an executive at the employee’s company or organization. “The e-mail is sent to an employee in the payroll or human resources departments, requesting a list of all employees and their Forms W-2,” the alert said. This strategy — sometimes referred to as business e-mail compromise (BEC) or business e-mail spoofing (BES) — first appeared during last year’s tax season. This time around, however, the cyber criminals are asking payroll employees to wire transfer funds to a certain account, which has resulted in job loss and thousands of dollars lost.

The latest “State of the Phish” report from Wombat Security Technologies found that while phishing attacks lowered 10 percent overall last year, users in the education industry were still twice as likely to fall for phishing e-mails (clicking through these e-mails 30 percent of the time compared to the national average of 15 percent). These findings suggest that e-mail phishing continues to be a highly effective cyberattack that results in serious damage to a company’s and employee’s critical data and information.

The Consortium for School Networking (CoSN), which is closely monitoring the situation, has issued its own alert, directing its members to the EdTech Strategies web page with real-time updates on the situation. A list of school districts that have been impacted by the W-2 phishing and wire transfer scam is available on the web page here. For more information, watch the video report from ABC Action News below. 

About the Author

Sri Ravipati is Web producer for THE Journal and Campus Technology. She can be reached at [email protected].

Featured

  • robot typing on a computer

    Microsoft Unveils 'Computer Use' Automation in Copilot Studio

    Microsoft has announced a new AI-powered feature called "computer use" for its Copilot Studio platform that allows agents to directly interact with Web sites and desktop applications using simulated mouse clicks, menu selections and text inputs.

  • AI microchip under cybersecurity attack, surrounded by symbols of threats like a skull, spider, lock, and warning shield

    Report Finds Agentic AI Protocol Vulnerable to Cyber Attacks

    A new report from Backslash Security has identified significant security vulnerabilities in the Model Context Protocol (MCP), technology introduced by Anthropic in November 2024 to facilitate communication between AI agents and external tools.

  • educators seated at a table with a laptop and tablet, against a backdrop of muted geometric shapes

    HMH Forms Educator Council to Inform AI Tool Development

    Adaptive learning company HMH has established an AI Educator Council that brings together teachers, instructional coaches and leaders from school district across the country to help shape its AI solutions.

  • illustration of a human head with a glowing neural network in the brain, connected to tech icons on a cool blue-gray background

    Meta Introduces Stand-Alone AI App

    Meta Platforms has launched a stand-alone artificial intelligence app built on its proprietary Llama 4 model, intensifying the competitive race in generative AI alongside OpenAI, Google, Anthropic, and xAI.