A spoofed email impersonating a company executive tricked a Main Line Health employee into emailing the W-2 and personal data of all ~11,000 staff to criminals.
Reviewed by the Social Engineering Examples team.
On February 16, 2016, an employee at Main Line Health received an email that appeared to come from a company executive requesting employee information. Believing it legitimate, the employee replied with personal data on essentially the entire workforce, reported as nearly 11,000 employees. The compromised data included names, home addresses, dates of birth, salaries, and Social Security numbers (W-2 information). No patient information was involved. Main Line Health said it recognized the incident on/around March 1, 2016, shortly after the IRS issued national alert IR-2016-34 warning payroll and HR staff about an emerging executive-spoof W-2 phishing scheme; a review prompted by that warning surfaced the earlier response. The health system publicly disclosed the breach on March 2, 2016, alerted the IRS and FBI (who investigated), and offered affected employees free credit monitoring and a dedicated call center. This is a well-documented, confirmed incident corroborated by first-party company statements, major regional news outlets, and the IRS's own contemporaneous alert.
This was a business-email-compromise style "CEO fraud" against a payroll/HR function. The attacker sent a spoofed email crafted to look as though it came from a senior Main Line Health executive, asking for a routine-seeming list of employee details or W-2 data. The request rode on a familiar workflow: HR and payroll legitimately handle bulk employee PII and W-2s during tax season, so a demand for that exact data did not look out of place. The recipient acted on perceived authority and did not out-of-band verify the sender before replying with the full dataset. Because the message asked for information already in the employee's reach, no malware, credential theft, or system intrusion was needed; the data simply walked out in a reply email.
Lure: an email appearing to be from a named company executive requesting employee W-2s or a roster with names, SSNs, dates of birth, addresses, and salaries, timed to tax-filing season when such requests seem plausible. The IRS alert quoted characteristic wording such as "Kindly send me the individual 2015 W-2 (PDF) and earnings summary of all W-2 of our company staff for a quick review." Tells: an executive emailing HR/payroll directly for bulk sensitive data rather than going through normal systems; a request to send SSNs/W-2s by email or attachment; urgency ("asap"); and a reply-to or sender address that does not exactly match the executive's real internal address. Verifying the request through a known phone number or in person would have exposed it.
Personal data (including SSNs) for approximately 11,000 employees was exposed to criminals, putting the entire workforce at risk of tax-refund fraud and identity theft. Main Line Health disclosed the incident, notified the IRS and FBI, filed breach notifications, provided free credit monitoring and a support call center, and said it was reviewing internal policies and safeguards. CEO Jack Lynch publicly urged other health care organizations and regional businesses to educate employees about phishing. No patient data was affected. No public arrest or dollar-loss figure has been tied to this specific incident.
This is a textbook example of the 2016 tax-season W-2 phishing wave that the IRS warned about in IR-2016-34 and that CSO Online tracked hitting 41+ organizations in Q1 2016. It shows that a single trusted reply, with no malware and no hacking, can expose an entire workforce's most sensitive data, and that healthcare organizations are targeted for employee data, not just patient records. It also illustrates a durable control lesson: bulk PII/W-2 requests, even from an apparent executive, must be verified out-of-band before fulfillment.
Require out-of-band verification (a call to a known number, not a reply) for any request for bulk employee PII, W-2s, or SSNs, regardless of apparent sender seniority. Enforce that sensitive data is never sent by email reply/attachment; route it through access-controlled systems. Deploy email authentication (SPF/DKIM/DMARC) and external-sender/display-name-spoofing warnings. Restrict who can access full employee datasets and add approval gates for bulk exports. Run tax-season-timed phishing awareness for payroll/HR staff specifically. Report W-2 losses fast to dataloss@irs.gov and the FBI IC3 so protective measures can be taken for employees.
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…