Now that Tax Season 2017 is upon us, it is time for HR departments to remain vigilant against the pervasive threat of identity theft and refund fraud arising from the distribution of personal tax information, say guest posters Ken Dort and Reeva Thakrar, both attorneys for the firm of Drinker Biddle & Reath.
Most often, these types of attacks come in the form of socially-engineered requests for employee W-2 forms.
In particular, recent tax schemes have begun with a fake phone call or phishing scam targeted at an HR or accounting department with the goal of receiving unauthorized access to an employee’s W-2 information or social security number. Phishing attacks usually involve sending emails that link to a website.
After the recipient clicks on the link, the website prompts individuals to enter valuable personal or financial information for a fake purpose. Fraud experts might also disguise their email addresses (e.g., by changing a zero to a capital letter “O”) and pretend they are employees requesting personal information via email.
Once the criminals receive this information, they will submit a fake tax return to the IRS depriving a taxpayer of the opportunity to receive their refund checks on a timely basis. The fraudsters only need a name, date of birth and social security number to file a fake return. They will also ensure the payout is modest, so as to avoid attracting any attention, and will submit a new address at which to receive the funds. In one day, criminals can fill in over fifteen returns and can expect their refund checks in about seven days.
As of March 5, 2016, the IRS reported that it identified 42,148 fraudulent tax returns with $227 million claimed in refunds. Fortunately, the IRS has been cracking down on these schemes and prevented the issuance of $180.6 million (79.6 percent) in fraudulent refund claims in 2016. However, despite their efforts, the IRS still failed to prevent the payment of almost $50 million in refunds that were fraudulent.
To make matters worse, victims affected by these schemes will not discover that they were attacked until they submit their own tax returns. At this point, the criminal has probably already received his check and is long gone with the money. While the IRS does keep records of earned wages and income reported by taxpayers’ employers, it does not review these records until several months after it issues the refund checks. As a result, some victims entitled to refunds did not receive their money for almost a year after attempting to file their actual returns.
For the 2017 season, the IRS has added several new features keying on the use of verification codes and the implementation of several dozen new data elements with electronically-filed tax returns all aimed to help ensure the authenticity of tax software users, but we have yet to see how effective these new measures will be.
What can you do to prepare?
We recommend taking the following steps to help keep your employees’ personal information safe:
- Training: Conduct annual training with at least your HR and accounting departments to make them aware of the latest schemes. The training should also remind members of these teams to never send social security numbers, W-2s, and other sensitive financial and personal information via email or phone to anyone.
- W-2 Delivery: Create and implement a secure method for sending annual W-2s to employees. If sending electronically, we recommend distributing the documents through a secure file sharing portal; otherwise you may send them in the mail. Ensure employees are reviewing and updating their addresses periodically, or at least annually.
- Risk Management: Implement risk management procedures, such as requiring HR and accounting teams to forward information about suspicious communications to management and requiring supervisor/management approval before responding to any requests for information via email or phone.
- Information sharing: Provide alerts and updates to your departments when potential incidents are discovered. Continue to monitor the IRS website for alerts and distribute these alerts to your team.
- Action Plan: Create an action plan detailing your organization’s response in case of an identity theft incident.
Remember, the IRS generally does not initiate contact with taxpayers or their employers by email, text message or other social media to request personal or financial information.
If you do receive an unsolicited email that appears to be from either the IRS or an organization closely linked to the IRS, such as the Electronic Federal Tax Payment System, report it by sending it to email@example.com.
Any individuals affected by a tax fraud scheme may report the incident to the IRS by following their instructions.
Ken Dort is a partner at Drinker Biddle & Reath LLP. He can be reached at Kenneth.Dort@dbr.com or (312) 569-1458.
Reeya Thakrar is an associate at Drinker Biddle & Reath LLP. She can be reached at firstname.lastname@example.org or (312) 569-1467.