A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan Spiegel's identity, part of a nationwide spring-2016 wave of spoofed-executive W-2 phishing that prompted an IRS public alert.
Reviewed by the Social Engineering Examples team.
In late February 2016, a member of Snap Inc.'s payroll department received an email that spoofed/impersonated CEO Evan Spiegel and requested employee payroll information. The employee complied and sent the data externally. Snap's own breach notice dates the fraudulent email to Feb. 26, 2016; the company publicly disclosed the incident on Feb. 28, 2016 via a blog post titled "An Apology to Our Employees" (the original blog.snapchat.com URL is now dead/unresolvable and has no Wayback Machine snapshot, but its full text is verbatim-republished by DataBreaches.net and quoted identically by numerous 2016 outlets). Contemporaneous press reporting (LA Times, Sky News, TechCrunch, Ars Technica, NBC News) put the number of affected current and former employees at approximately 700, though Snap's own public statement did not give a precise count. Per Sky News and LA Times reporting, the employee herself realized roughly 15 minutes after replying that the request was fraudulent and proactively re-contacted Spiegel, who confirmed she had been conned, a finer-grained, individual-level timeline distinct from (and not contradicting) Snap's official company-level statement that it confirmed the attack was isolated and reported it to the FBI within about four hours. The exposed data, per Snap's Employee Notice of Data Breach filed with the California Attorney General, included names, Snapchat employee IDs, Social Security numbers, state of residence and work, 2015 wages (including any stock-option gains), company-paid life/health insurance costs, relocation reimbursements, retirement/dependent-care/healthcare plan contributions, additional required payments, and taxes withheld, i.e., full W-2-equivalent payroll/tax data. Snap said no internal systems were breached and no Snapchat user data was accessed; the exposure was limited to the payroll dataset the deceived employee sent out. The incident occurred amid a nationwide wave of similar spoofed-executive W-2 phishing attacks in early 2016 that prompted the IRS to issue a public alert (IR-2016-34, March 3, 2016) to payroll and HR professionals, and which the FBI later characterized as the "W2-PII twist" on business email compromise.
A payroll/HR employee at Snap Inc. received an email that spoofed or impersonated CEO Evan Spiegel, requesting employee payroll information. Believing the request was legitimate and urgent (consistent with the classic CEO-fraud pattern of authority + urgency), the employee compiled and sent the requested payroll data to the external attacker via email reply. Per contemporaneous press reporting (Sky News, LA Times), the employee realized roughly 15 minutes after replying that the request was fraudulent and proactively re-contacted Evan Spiegel directly, who confirmed the employee had been conned; separately, Snap's official company-level statement said the incident was confirmed as isolated and reported to the FBI within about four hours of the phishing email. These are two distinct, non-contradictory timelines: the employee's own ~15-minute self-catch, and the company's ~4-hour formal isolation/FBI-notification confirmation. Snap said no internal company systems were breached and no Snapchat user data was accessed; the compromise was limited to a single employee's response to a socially-engineered email request, not a technical intrusion.
Lure: an email designed to look like it came from CEO Evan Spiegel, sent directly to a payroll-department employee, requesting compilation and transmission of employee payroll/W-2 data, exploiting the authority of the CEO's name and the routine nature of payroll data requests during tax season. Tell (in hindsight/for training): any request for bulk employee PII or W-2 data purportedly from an executive, arriving by email alone, requesting an unusual bypass of normal payroll-release procedures, urgent in tone, and not verifiable through a secondary channel (phone, in-person, or established request workflow). This is the hallmark pattern the IRS flagged across dozens of similar 2016 incidents. Notably, the Snap employee did catch the deception herself about 15 minutes after replying, once she paused and contacted Spiegel directly to double-check, illustrating that even a delayed secondary-channel verification, done immediately after the fact, is far better than none.
Snap Inc. publicly apologized to employees via a Feb. 28, 2016 blog post titled "An Apology to Our Employees," confirmed it had reported the incident to the FBI, said the phishing attack was isolated within about four hours, and offered two years of free identity-theft monitoring and insurance (through ID Experts/MyIDCare, enrollment deadline May 1, 2016) to all affected current and former employees. It filed an Employee Notice of Data Breach with the California Attorney General's office. No internal systems or user data were reported compromised; the impact was limited to the payroll dataset sent out by the deceived employee. No known criminal charges or attacker attribution were publicly announced in connection with this specific incident (a distinct, unrelated 2020-2021 Snapchat account-hacking case involving SIM-swap-style access-code phishing to steal user photos, for which Kyle Svara and Steve Waithe were later charged, should not be conflated with this 2016 payroll incident).
This is one of the most widely cited early examples of the "W-2 phishing" sub-variant of CEO fraud/BEC: rather than tricking finance staff into wiring money, attackers trick payroll/HR staff into emailing back an entire company's worth of employee tax and PII data in one shot, creating durable identity-theft and tax-fraud risk for hundreds of individuals who were never themselves targeted or at fault. It illustrates how a single spoofed email, with no technical intrusion into any system, can produce a mass PII breach purely through social engineering of one employee, and how routine, seasonally-predictable business processes (year-end/tax-season W-2 distribution) create a reliable pretext attackers exploit at scale across many organizations simultaneously, as evidenced by the IRS having to issue a sector-wide alert the same week. It is also a useful case study in verification timing: the deceived employee independently caught her own mistake within minutes and self-reported, which sped remediation, underscoring that immediate self-correction and reporting, even after the fact, meaningfully limits the blast radius of a social-engineering failure.
Snap's own remediation: it said it detected and isolated the incident within four hours of the fraudulent email, reported it to the FBI, and pledged to "redouble" security and privacy training for employees, particularly in finance/payroll functions handling sensitive data. Broader defenses recommended by the IRS and FBI in response to this wave of attacks (IR-2016-34, FBI BEC advisories) included: verifying any request for bulk employee PII/W-2 data via a second channel (phone call to a known number, in-person confirmation) before sending, especially requests marked urgent or confidential from an executive; implementing internal controls requiring two-person authorization for release of bulk payroll/tax data; training payroll/HR/accounting staff specifically on spoofed-executive email patterns (reply-to mismatches, urgency, off-hours timing, unusual requests bypassing normal process); using email authentication (SPF/DKIM/DMARC) to reduce domain spoofing; and encouraging any organization victimized to report to the IRS (dataloss@irs.gov) and FBI IC3 immediately so W-2 data can be flagged for fraudulent-return monitoring.
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…