Case Library / Phishing / Snapchat W-2 Payroll Phishing Breach (2016)

Snapchat W-2 Payroll Phishing Breach (2016)

A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan Spiegel's identity, part of a nationwide spring-2016 wave of spoofed-executive W-2 phishing that prompted an IRS public alert.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In late February 2016, a member of Snap Inc.'s payroll department received an email that spoofed/impersonated CEO Evan Spiegel and requested employee payroll information. The employee complied and sent the data externally. Snap's own breach notice dates the fraudulent email to Feb. 26, 2016; the company publicly disclosed the incident on Feb. 28, 2016 via a blog post titled "An Apology to Our Employees" (the original blog.snapchat.com URL is now dead/unresolvable and has no Wayback Machine snapshot, but its full text is verbatim-republished by DataBreaches.net and quoted identically by numerous 2016 outlets). Contemporaneous press reporting (LA Times, Sky News, TechCrunch, Ars Technica, NBC News) put the number of affected current and former employees at approximately 700, though Snap's own public statement did not give a precise count. Per Sky News and LA Times reporting, the employee herself realized roughly 15 minutes after replying that the request was fraudulent and proactively re-contacted Spiegel, who confirmed she had been conned, a finer-grained, individual-level timeline distinct from (and not contradicting) Snap's official company-level statement that it confirmed the attack was isolated and reported it to the FBI within about four hours. The exposed data, per Snap's Employee Notice of Data Breach filed with the California Attorney General, included names, Snapchat employee IDs, Social Security numbers, state of residence and work, 2015 wages (including any stock-option gains), company-paid life/health insurance costs, relocation reimbursements, retirement/dependent-care/healthcare plan contributions, additional required payments, and taxes withheld, i.e., full W-2-equivalent payroll/tax data. Snap said no internal systems were breached and no Snapchat user data was accessed; the exposure was limited to the payroll dataset the deceived employee sent out. The incident occurred amid a nationwide wave of similar spoofed-executive W-2 phishing attacks in early 2016 that prompted the IRS to issue a public alert (IR-2016-34, March 3, 2016) to payroll and HR professionals, and which the FBI later characterized as the "W2-PII twist" on business email compromise.

How the Attack Worked

A payroll/HR employee at Snap Inc. received an email that spoofed or impersonated CEO Evan Spiegel, requesting employee payroll information. Believing the request was legitimate and urgent (consistent with the classic CEO-fraud pattern of authority + urgency), the employee compiled and sent the requested payroll data to the external attacker via email reply. Per contemporaneous press reporting (Sky News, LA Times), the employee realized roughly 15 minutes after replying that the request was fraudulent and proactively re-contacted Evan Spiegel directly, who confirmed the employee had been conned; separately, Snap's official company-level statement said the incident was confirmed as isolated and reported to the FBI within about four hours of the phishing email. These are two distinct, non-contradictory timelines: the employee's own ~15-minute self-catch, and the company's ~4-hour formal isolation/FBI-notification confirmation. Snap said no internal company systems were breached and no Snapchat user data was accessed; the compromise was limited to a single employee's response to a socially-engineered email request, not a technical intrusion.

The Lure & the Tell

Lure: an email designed to look like it came from CEO Evan Spiegel, sent directly to a payroll-department employee, requesting compilation and transmission of employee payroll/W-2 data, exploiting the authority of the CEO's name and the routine nature of payroll data requests during tax season. Tell (in hindsight/for training): any request for bulk employee PII or W-2 data purportedly from an executive, arriving by email alone, requesting an unusual bypass of normal payroll-release procedures, urgent in tone, and not verifiable through a secondary channel (phone, in-person, or established request workflow). This is the hallmark pattern the IRS flagged across dozens of similar 2016 incidents. Notably, the Snap employee did catch the deception herself about 15 minutes after replying, once she paused and contacted Spiegel directly to double-check, illustrating that even a delayed secondary-channel verification, done immediately after the fact, is far better than none.

Outcome

Snap Inc. publicly apologized to employees via a Feb. 28, 2016 blog post titled "An Apology to Our Employees," confirmed it had reported the incident to the FBI, said the phishing attack was isolated within about four hours, and offered two years of free identity-theft monitoring and insurance (through ID Experts/MyIDCare, enrollment deadline May 1, 2016) to all affected current and former employees. It filed an Employee Notice of Data Breach with the California Attorney General's office. No internal systems or user data were reported compromised; the impact was limited to the payroll dataset sent out by the deceived employee. No known criminal charges or attacker attribution were publicly announced in connection with this specific incident (a distinct, unrelated 2020-2021 Snapchat account-hacking case involving SIM-swap-style access-code phishing to steal user photos, for which Kyle Svara and Steve Waithe were later charged, should not be conflated with this 2016 payroll incident).

Why It Matters

This is one of the most widely cited early examples of the "W-2 phishing" sub-variant of CEO fraud/BEC: rather than tricking finance staff into wiring money, attackers trick payroll/HR staff into emailing back an entire company's worth of employee tax and PII data in one shot, creating durable identity-theft and tax-fraud risk for hundreds of individuals who were never themselves targeted or at fault. It illustrates how a single spoofed email, with no technical intrusion into any system, can produce a mass PII breach purely through social engineering of one employee, and how routine, seasonally-predictable business processes (year-end/tax-season W-2 distribution) create a reliable pretext attackers exploit at scale across many organizations simultaneously, as evidenced by the IRS having to issue a sector-wide alert the same week. It is also a useful case study in verification timing: the deceived employee independently caught her own mistake within minutes and self-reported, which sped remediation, underscoring that immediate self-correction and reporting, even after the fact, meaningfully limits the blast radius of a social-engineering failure.

Defenses

Snap's own remediation: it said it detected and isolated the incident within four hours of the fraudulent email, reported it to the FBI, and pledged to "redouble" security and privacy training for employees, particularly in finance/payroll functions handling sensitive data. Broader defenses recommended by the IRS and FBI in response to this wave of attacks (IR-2016-34, FBI BEC advisories) included: verifying any request for bulk employee PII/W-2 data via a second channel (phone call to a known number, in-person confirmation) before sending, especially requests marked urgent or confidential from an executive; implementing internal controls requiring two-person authorization for release of bulk payroll/tax data; training payroll/HR/accounting staff specifically on spoofed-executive email patterns (reply-to mismatches, urgency, off-hours timing, unusual requests bypassing normal process); using email authentication (SPF/DKIM/DMARC) to reduce domain spoofing; and encouraging any organization victimized to report to the IRS (dataloss@irs.gov) and FBI IC3 immediately so W-2 data can be flagged for fraudulent-return monitoring.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: The attacker likely identified Snap Inc.'s CEO (Evan Spiegel, a public, well-known figure) and the existence of a payroll/HR function to target, typically via a combination of public sources such as LinkedIn, company press coverage, and corporate filings, consistent with how the FBI and IRS describe this wave of spoofed-executive scams identifying which company officer to impersonate and which department handles payroll data.
Countering Stage 1: Public information about who a company's CEO is and that it has a payroll department is not realistically suppressible; the practical control lies downstream, in hardening payroll's process for handling any request that invokes an executive's name rather than trying to hide who the executive is.
2
Infrastructure setup: The attacker likely registered or used a look-alike or spoofable sender identity designed to appear as Evan Spiegel's email, a low-cost, widely available technique (domain spoofing or a similarly-named free-mail account) that IRS and FBI advisories describe as the standard delivery mechanism for this scam wave, requiring no system intrusion into Snap Inc. itself.
Countering Stage 2: Email authentication standards (SPF, DKIM, DMARC) enforced on the receiving domain reduce the odds that a spoofed or look-alike sender address reaches the inbox looking legitimate, or at least trigger a visible external-sender warning banner.
3
Targeting the recipient: The attacker identified and addressed a specific payroll-department employee at Snap Inc. rather than a generic inbox, consistent with the IRS's description of this scheme as directed at named individuals in payroll or HR roles who have the authority and access to compile bulk employee data.
Countering Stage 3: Restricting which employees can receive and act on bulk-PII requests, and flagging emails from executives to non-standard recipients (payroll/HR) requesting sensitive data, narrows the attack surface an attacker can target.
4
Pretext delivery: The attacker sent an email impersonating CEO Evan Spiegel directly to the payroll employee, requesting employee payroll/W-2 information, using the authority of the CEO's name and the routine, tax-season-driven plausibility of such a request to bypass suspicion, per Snap's own breach notice and IRS alert IR-2016-34.
Countering Stage 4: Staff training specifically on the pattern of spoofed-executive requests for W-2/PII data, per IRS guidance issued in the same wave of attacks, helps an employee recognize the pretext even when the request looks authoritative and urgent.
5
Compliance and data compilation: The targeted employee, believing the request legitimate and urgent, compiled the requested payroll data (names, Social Security numbers, wages, benefits, and related W-2 fields) as detailed in Snap's Employee Notice of Data Breach filed with the California Attorney General.
Countering Stage 5: A mandatory secondary-channel verification (a phone call to a known number, or in-person confirmation) before compiling or releasing any bulk employee PII or W-2 data, regardless of who appears to be asking, is the single control that would have stopped this incident before data was compiled.
6
Exfiltration via reply: The employee emailed the compiled payroll data directly back to the attacker's spoofed address, completing the data handoff entirely through a normal-looking email reply with no malware, credential theft, or network intrusion involved, per Snap's public statement that no internal systems were breached.
Countering Stage 6: Data-loss-prevention tooling on outbound email that detects patterns indicative of Social Security numbers or bulk PII and blocks or flags the message before it leaves the network, plus requiring two-person authorization for release of bulk payroll/tax data, catches the exfiltration step even if verification failed earlier.
7
Objective completion: The attacker obtained full W-2-equivalent PII for roughly 700 current and former Snap employees, data valuable for tax-refund fraud or resale, achieving the scheme's objective before Snap's four-hour internal isolation and FBI notification could intercept the exfiltrated data.
Countering Stage 7: Rapid internal detection and isolation, exactly what Snap Inc. did within about four hours, combined with prompt FBI/IRS notification so the exposed Social Security numbers can be flagged for fraudulent-return monitoring, limits the downstream harm once data has already left the organization.
Quick Facts
Victim
Snap Inc. (Snapchat), approximately 700 current and former employees
Location
Venice/Los Angeles, California, USA (Snap Inc. headquarters)
Date
2016-02-26 (attack); disclosed 2016-02-28
Impact
No direct financial theft of company funds was reported (unlike wire-transfer BEC scams); the loss was data exposure of an estimated ~700 current and former employees' PII, creating downstream identity-theft and fraudulent tax-return risk. Snap incurred costs for two years of identity-theft monitoring/insurance (via ID Experts/MyIDCare) for all affected individuals, incident response, and reputational/legal exposure (California AG data-breach notification filing). No dollar figure for the monitoring program cost or total incident cost has ever been publicly disclosed; this is a genuine absence of data, not an unverified claim.
Status
Confirmed
Case Type
Real-World Incident
Sector
Technology & Software
Related

Related Cases

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…

Incident 2016Read →

Pivotal Labs W-2 Phishing (CEO-Spoof), 2016

A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…

Incident 2016Read →

Ubiquiti Networks $46.7M business email compromise (2015)

Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…

Incident 2015Read →