A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015 W-2s for every GCI, Denali Media, UUI and Unicom worker.
Reviewed by the Social Engineering Examples team.
In February 2016, GCI's payroll department received an email in which a third party impersonated the company's chief financial officer (identified in press reporting as CFO Pete Pounds) and requested copies of the W-2 Wage and Tax Statement forms for everyone who worked for GCI during calendar year 2015. According to GCI's own breach notification, the payroll employee who received the message "correctly questioned the request as unusual," but the impersonator persisted, and the employee ultimately emailed the requested W-2 information to the outside party on February 24, 2016. GCI discovered the disclosure on March 3, 2016 and notified employees and regulators shortly after. The company believes the 2015 W-2s of all employees who worked for GCI, Denali Media, UUI and Unicom at any time during 2015 were disclosed. Each W-2 included the person's Social Security number, name and address, and 2015 income and tax-withholding information. GCI emphasized that no IT systems or networks were breached and no customer information was affected. This was a real, documented incident, confirmed by GCI's breach-notification letter filed with the Montana Department of Justice and corroborated by contemporaneous reporting.
This is a business email compromise (BEC) variant known as CEO/CFO-spoof W-2 phishing. Rather than deploying malware or breaking into systems, the attacker abused trust and authority: an email crafted to appear to come from a senior executive asked a payroll staffer for a bulk of sensitive tax documents. It succeeded because the request came, apparently, from a known, high-ranking person; because tax season made a request for W-2s plausible; and because the attacker applied social pressure. Notably, the employee's instincts were correct: they flagged the request as unusual. The failure was that the doubt was resolved by continued email exchange with the attacker instead of by out-of-band verification (a phone call or in-person check with the real CFO). The attacker's persistence overcame the initial hesitation.
Lure: an email purporting to be from GCI's CFO asking payroll to send the full set of 2015 employee W-2 forms. Tells: an executive making an unusual bulk data request over email; pressure and insistence when questioned; a request routed to a single payroll employee rather than through normal channels; and timing during tax-filing season when W-2 requests can seem routine. The reliable defense is out-of-band verification of any executive request for bulk employee or financial data, using a known phone number or in-person contact, never by replying to the email itself.
GCI's incident response team interviewed the relevant employees, preserved evidence, and notified the FBI. The company notified all affected employees, filed breach notifications with state authorities, and offered two years of free AllClear ID credit monitoring, identity-theft counseling, and identity-theft insurance. Employees were urged to file IRS Form 14039 (Identity Theft Affidavit) to guard against fraudulent 2015 tax returns. GCI said it would strengthen protections and launch an anti-phishing training program. No public attribution or arrest followed. The incident was one of 41+ organizations hit by W-2 BEC phishing in Q1 2016, a wave that prompted an IRS payroll/HR alert (IR-2016-34).
The GCI case is a textbook example of why W-2/payroll phishing is dangerous and why human vigilance alone is not enough. The targeted employee actually recognized the request as suspicious yet still complied under persistence, showing that awareness must be paired with a mandatory verification procedure that removes judgment-under-pressure from the equation. A single successful email exposed the SSNs and income data of thousands of people, with no malware and no network intrusion, making it cheap for attackers and devastating for victims. It also sits within a documented 2016 epidemic of executive-spoof W-2 scams serious enough to trigger a federal IRS warning, underscoring that this is a repeatable, industrialized tactic rather than a one-off.
Require out-of-band verification (phone or in-person to a known contact) for any request for bulk W-2, payroll, or employee PII, regardless of who appears to be asking. Establish a policy that no single employee can release mass sensitive data on email authority alone; route such requests through a defined approval workflow. Deploy email authentication (SPF/DKIM/DMARC) and display-name/lookalike-domain warnings to flag executive impersonation. Give payroll/HR and finance targeted anti-phishing and BEC training with a psychologically safe path to escalate and refuse suspicious requests, so persistence pressure cannot override initial doubt. Minimize and encrypt stored W-2/PII, and pre-plan breach response (IRS Form 14039 guidance, credit monitoring) so victims can act fast.
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…