A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs and earnings for several thousand US employees.
Reviewed by the Social Engineering Examples team.
On March 1, 2016, an employee in Seagate's HR/payroll function received a targeted phishing email crafted to look like an internal request from a senior executive (news reporting identifies the spoofed sender as CEO Stephen Luczo) asking for all 2015 Forms W-2. Believing it was a legitimate internal company request, the employee sent the actual W-2 data for every current and former US-based Seagate (and Seagate-affiliate) employee to an unauthorized outside party. Seagate learned of the disclosure the same day, notified the IRS and federal law enforcement, and later mailed formal breach-notification letters (filed with the California Attorney General and other state regulators). The exposed data included names, addresses, Social Security numbers, and earnings. Spokesman Eric DeRitis put the affected count at "several thousand" but "less than 10,000 by a good amount." This is a confirmed, documented incident: the primary source is Seagate's own breach-notice letter, corroborated by KrebsOnSecurity (which broke the story) and multiple outlets.
The attack was a business-email-compromise-style whaling request: an email impersonating a trusted authority figure (the CEO) sent to staff who legitimately handle sensitive tax records. The request itself, gathering W-2s at tax season, was plausible and routine for a payroll employee, so it did not trigger suspicion. There was no malware or system intrusion; the exploit was entirely social. The attack landed in the narrow window when W-2 preparation is a normal internal activity, the same day as an IRS public warning about exactly this scam (IR-2016-34, issued March 1, 2016), maximizing believability. Once the recipient trusted the apparent sender and the ordinary-looking ask, they voluntarily emailed a spreadsheet of tax data outside the company.
Lure: an email appearing to come from the CEO to HR/payroll requesting copies of all 2015 employee W-2 forms, framed as a normal executive request during tax season. Tells (as later reinforced by Seagate's own remediation): a bulk request for highly sensitive tax/PII data delivered by email rather than through established payroll systems, sender authority used to short-circuit verification, and no out-of-band confirmation of the request. The IRS issued a public alert about this precise CEO-spoof W-2 scheme (IR-2016-34) that very day, March 1, 2016.
W-2 data for several thousand US employees was in criminal hands, with tax-refund fraud as the primary downstream risk; some affected employees later reported fraudulent tax returns filed in their names. Seagate notified the IRS (which added extra scrutiny/watches to affected employees' tax accounts to block fraudulent refunds) and federal law enforcement, sent breach notifications, stood up an Epiq-run call center, offered two years of free Experian ProtectMyID credit monitoring with $1,000,000 identity-theft insurance, and pledged additional phishing training and process changes. No public attribution or arrest was reported. The breach also spawned employee class-action litigation (Castillo et al. v. Seagate Technology LLC), which Seagate settled in 2018 with extended identity-theft protection and additional data-security commitments for the class.
This is a textbook example of how a purely social attack, no malware, no hacking, can exfiltrate an entire company's most sensitive employee data through one trusted person. It shows why CEO-spoof/W-2 whaling is so effective: it weaponizes authority plus a seasonally plausible request against a role that routinely handles the exact data being sought. It also illustrates that credit monitoring is a weak remedy for W-2 loss, since the real harm, fraudulent tax filings using stolen SSNs and earnings, is not prevented by credit alerts. Seagate was one of many 2016 victims of an IRS-warned wave, underscoring that awareness alone did not stop it.
Require out-of-band verification (phone/known channel) for any bulk request for W-2s, PII, or payroll/tax data, regardless of who appears to be asking. Never transmit W-2/tax data by email; route it only through controlled systems with access logging. Treat executive email requests as impersonation risk: deploy sender-authentication (DMARC/DKIM/SPF), external-sender banners, and lookalike/display-name spoofing detection. Restrict who can export bulk W-2 data and add a second-approver control on such exports. Run targeted anti-phishing training for HR/finance/payroll during tax season specifically on CEO-fraud and W-2 requests. Have an incident playbook that includes immediate IRS notification so employee tax accounts can be flagged before fraudulent refunds are filed.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…