A W-2 contains precisely the type of information criminals can use to impersonate taxpayers: name, Social Security number, employer and wage information. The IRS has long warned about business-email-compromise schemes in which a criminal impersonates an executive and asks payroll or HR to send employee W-2s. That makes a W-2 incident more than a generic privacy event — it can create tax-related identity-theft risk in addition to credit and account fraud.
Key Takeaways
- For a W-2 data loss, IRS guidance directs businesses to email dataloss@irs.gov with "W2 Data Loss" in the subject and the requested business/contact facts.
- Do not attach employee personally identifiable information (PII) to the IRS reporting email.
- The IRS points businesses toward state tax-agency reporting resources through the Federation of Tax Administrators.
- W-2 theft can create tax-related identity risk because it combines Social Security and wage information.
- Practical controls include treating requests for bulk W-2/SSN data as a high-risk transaction.
Exact IRS Reporting Facts
For a W-2 data loss, IRS guidance says to email dataloss@irs.gov and include: business name; Employer Identification Number (EIN) associated with the loss; contact name; contact phone number; summary of how the loss occurred; and volume of employees affected. Do not attach employee PII.
For a W-2 scam/phishing email, follow the IRS reporting instructions at the current IRS fraud-reporting page. The IRS also points businesses to state tax-agency reporting resources through the Federation of Tax Administrators.
The Employer Response Sequence
1. Stop and preserve
Contain the compromised account or workflow, preserve the phishing message and relevant logs, and engage the organization's incident-response/security and legal resources. Do not destroy evidence in the rush to notify people.
2. Notify the IRS through the published W-2 data-loss process
Use the current IRS instructions. Send only the business/contact facts requested. Do not email the stolen W-2 files or employee PII to the IRS reporting mailbox.
3. Coordinate state reporting
The IRS points businesses toward the Federation of Tax Administrators for state data-breach contacts. Because legal obligations can differ by state and circumstance, qualified counsel should determine the required notifications.
4. Communicate with employees
Employees should receive a factual explanation of what data was involved, what the employer is doing, and where to find legitimate federal resources. Relevant resources can include IdentityTheft.gov, IRS tax-identity information, and FTC credit-freeze/fraud-alert guidance.
5. Fix the process that allowed the request through
| Recommended control | Why it matters |
|---|---|
| No bulk W-2 export based solely on email | Limits the phishing surface attackers exploit |
| Two-person approval for bulk employee tax-data release | Adds independent scrutiny on high-risk transactions |
| Out-of-band verification with the requester | Confirms the request through a known contact method |
| Least-privilege access and logging of exports | Controls and detects who accessed what data |
| Recurring phishing/BEC training for payroll/HR | Raises recognition of executive-impersonation schemes |
| A written escalation path for unusual executive requests | Provides an observable exception channel |
This framework is a Blackspire-advisory recommendation, not an IRS mandate.
Leadership Checklist
- Preserve the suspicious email and technical evidence.
- Confirm exactly what W-2/SSN data left the organization.
- Notify IRS through the current W-2 data-loss channel.
- Do not attach employee PII to the IRS reporting email.
- Identify affected states and engage qualified counsel.
- Prepare factual employee notice/support information.
- Direct employees only to verified government/benefit resources.
- Review bulk payroll-data access and approval controls.
- Assess whether current identity-restoration support is sufficient.
- Document actions and decisions.
Frequently Asked Questions
Evaluate Employee Identity-Protection Readiness
Blackspire can help leadership review whether existing legal/identity benefits, restoration support, and employee communication are adequate. This does not replace breach counsel or incident response. Confidential and without obligation.
Request a Confidential ReviewRelated Blackspire Resources
Legal & Identity Protection for Employers
Blackspire · Service
Employee Data Breach: What to Tell Workers When SSNs Are Exposed
Blackspire · Business Protection
Credit Freeze vs. Fraud Alert vs. Credit Monitoring vs. Identity Restoration
Blackspire · Business Protection
Cybersecurity Risk & Cost Review
Blackspire · Business Protection
Blackspire Insights
Blackspire · Resources
Sources & Methodology
- IRS — Form W-2/SSN Data Theft: Information for Businesses and Payroll Service Providers (irs.gov)
- IRS — Report fake IRS, Treasury or tax-related emails and messages (irs.gov)
- FTC — Data Breach Response: A Guide for Business and FTC Credit Freezes and Fraud Alerts (consumer.ftc.gov)
Disclaimer: Educational only. This article does not provide tax or legal advice. Confirm current IRS reporting instructions on the source page before future material updates; do not add employee PII to reporting emails.
Published: September 11, 2026 · Last Modified: September 11, 2026 · Publisher: Blackspire Advisors · Category: Business Protection