A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's U.S. workforce.
Reviewed by the Social Engineering Examples team.
On March 22, 2016, during U.S. tax-filing season, an unknown third party sent a Pivotal employee a fraudulent email crafted to look as though it came from CEO Rob Mee, requesting certain information about Pivotal employees. Believing the request was genuinely from the CEO, the employee replied with employees' 2015 Form W-2 data. Per multiple reports, the disclosure covered W-2 information for the company's U.S. employees. The exposed data included each person's name, address, 2015 income information, and Social Security Number or Individual Taxpayer Identification Number (ITIN). Pivotal notified law enforcement and the IRS, opened an investigation, and stated no customer data was affected. It provided affected employees three years of AllClear ID identity-protection at no cost, including AllClear ID's identity-repair hotline, plus a W2@pivotal.io contact for additional requests. The incident was first reported by SC Magazine and is documented in Pivotal's own breach notice filed with the California Attorney General (dated March 31, 2016), authored by chief people officer Joe Militello. All core facts are confirmed by that primary notice.
The attack is a "CEO fraud" / business email compromise variant aimed at data rather than money. The fraudster posed as the chief executive and made a plausible, in-character request for employee information, exploiting the reflexive deference employees show to a message that appears to come from the top of the org chart. Tax season made a request touching W-2 or payroll data unremarkable, lowering suspicion. Because the ask was for information (a reply with an attachment or list) rather than a wire transfer, it bypassed the financial-approval controls that might have caught a payment request. The single recipient's reply was enough to expose the whole workforce's tax records, giving criminals the exact fields needed to file fraudulent tax returns and commit identity theft.
The lure: an email appearing to be from CEO Rob Mee asking an employee for "certain information about Pivotal employees," landing during tax season when W-2 handling was routine. The tells (recognizable in hindsight): a sensitive bulk-data request arriving by email rather than through normal HR/payroll systems; the request coming top-down from an executive who would not normally handle W-2 files personally; and no independent verification via a second channel. As IRS Commissioner John Koskinen put it about this scam wave, "If your CEO appears to be emailing you for a list of company employees, check it out before you respond."
Pivotal employees' 2015 W-2 data (names, addresses, income, SSN/ITIN) was disclosed to criminals, exposing affected staff to tax-refund fraud and identity theft. Pivotal reported the incident to law enforcement and the IRS, filed a breach notice with the California AG, and offered three years of AllClear ID protection, including its identity-repair hotline. No attacker was publicly identified and the count of affected employees was not disclosed. Pivotal was one of dozens of organizations (alongside Snapchat, Seagate and others) hit by the same W-2 phishing wave in Q1 2016.
This is a textbook example of how impersonating authority plus well-timed, in-context framing defeats otherwise careful people, and how a data-request BEC sidesteps the money-movement controls that catch wire fraud. One employee's good-faith reply exposed an entire workforce's most identity-theft-ready records. It shows why sensitive-data requests need the same out-of-band verification discipline as payment requests, and it illustrates the seasonal, industrialized nature of W-2 phishing, which struck dozens of companies in the same weeks of 2016.
Route all bulk PII/W-2/payroll requests through defined HR or payroll workflows, never ad-hoc email replies. Require out-of-band verification (known phone number, in person, or a separate ticketing channel) for any request for employee tax or personal data, regardless of who it appears to come from. Treat unusual executive requests as a red flag and make it safe and expected to double-check. Use email authentication (SPF/DKIM/DMARC) and external-sender/display-name-spoofing warnings to flag look-alike senders. Restrict and log who can access and export W-2 datasets, apply least privilege, and require approval for bulk exports. Run tax-season-specific awareness training on CEO-fraud W-2 scams. Have an incident plan ready: notify law enforcement and the IRS, file required breach notices, and offer identity-protection and tax-fraud monitoring to affected staff.
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…