Employer W-2 data-theft response checklist for payroll and HR leaders
Business Protection10 min read

By Blackspire Advisors · Published September 11, 2026

W-2/SSN Data Theft: What Should an Employer Do After Payroll Information Is Stolen?

If an employer loses employee W-2 data, the IRS says time is critical. The business can notify the IRS at dataloss@irs.gov using the subject "W2 Data Loss" and should include business/contact information, a summary of how the loss occurred, and the number of employees affected — without attaching employee PII. Employers should also follow applicable state breach-reporting requirements and coordinate with qualified counsel.

A W-2 contains precisely the type of information criminals can use to impersonate taxpayers: name, Social Security number, employer and wage information. The IRS has long warned about business-email-compromise schemes in which a criminal impersonates an executive and asks payroll or HR to send employee W-2s. That makes a W-2 incident more than a generic privacy event — it can create tax-related identity-theft risk in addition to credit and account fraud.

Key Takeaways

  • For a W-2 data loss, IRS guidance directs businesses to email dataloss@irs.gov with "W2 Data Loss" in the subject and the requested business/contact facts.
  • Do not attach employee personally identifiable information (PII) to the IRS reporting email.
  • The IRS points businesses toward state tax-agency reporting resources through the Federation of Tax Administrators.
  • W-2 theft can create tax-related identity risk because it combines Social Security and wage information.
  • Practical controls include treating requests for bulk W-2/SSN data as a high-risk transaction.

Exact IRS Reporting Facts

For a W-2 data loss, IRS guidance says to email dataloss@irs.gov and include: business name; Employer Identification Number (EIN) associated with the loss; contact name; contact phone number; summary of how the loss occurred; and volume of employees affected. Do not attach employee PII.

For a W-2 scam/phishing email, follow the IRS reporting instructions at the current IRS fraud-reporting page. The IRS also points businesses to state tax-agency reporting resources through the Federation of Tax Administrators.

The Employer Response Sequence

1. Stop and preserve

Contain the compromised account or workflow, preserve the phishing message and relevant logs, and engage the organization's incident-response/security and legal resources. Do not destroy evidence in the rush to notify people.

2. Notify the IRS through the published W-2 data-loss process

Use the current IRS instructions. Send only the business/contact facts requested. Do not email the stolen W-2 files or employee PII to the IRS reporting mailbox.

3. Coordinate state reporting

The IRS points businesses toward the Federation of Tax Administrators for state data-breach contacts. Because legal obligations can differ by state and circumstance, qualified counsel should determine the required notifications.

4. Communicate with employees

Employees should receive a factual explanation of what data was involved, what the employer is doing, and where to find legitimate federal resources. Relevant resources can include IdentityTheft.gov, IRS tax-identity information, and FTC credit-freeze/fraud-alert guidance.

5. Fix the process that allowed the request through

Recommended control Why it matters
No bulk W-2 export based solely on email Limits the phishing surface attackers exploit
Two-person approval for bulk employee tax-data release Adds independent scrutiny on high-risk transactions
Out-of-band verification with the requester Confirms the request through a known contact method
Least-privilege access and logging of exports Controls and detects who accessed what data
Recurring phishing/BEC training for payroll/HR Raises recognition of executive-impersonation schemes
A written escalation path for unusual executive requests Provides an observable exception channel

This framework is a Blackspire-advisory recommendation, not an IRS mandate.

Leadership Checklist

  1. Preserve the suspicious email and technical evidence.
  2. Confirm exactly what W-2/SSN data left the organization.
  3. Notify IRS through the current W-2 data-loss channel.
  4. Do not attach employee PII to the IRS reporting email.
  5. Identify affected states and engage qualified counsel.
  6. Prepare factual employee notice/support information.
  7. Direct employees only to verified government/benefit resources.
  8. Review bulk payroll-data access and approval controls.
  9. Assess whether current identity-restoration support is sufficient.
  10. Document actions and decisions.

Frequently Asked Questions

Where does a business report a W-2 data loss to the IRS?
Should the employer attach the affected W-2 files?
Why is W-2 theft different from other employee-data breaches?
Should affected employees freeze their credit?
Does reporting to the IRS satisfy every breach-notification duty?

Evaluate Employee Identity-Protection Readiness

Blackspire can help leadership review whether existing legal/identity benefits, restoration support, and employee communication are adequate. This does not replace breach counsel or incident response. Confidential and without obligation.

Request a Confidential Review

Related Blackspire Resources

Sources & Methodology

  • IRS — Form W-2/SSN Data Theft: Information for Businesses and Payroll Service Providers (irs.gov)
  • IRS — Report fake IRS, Treasury or tax-related emails and messages (irs.gov)
  • FTC — Data Breach Response: A Guide for Business and FTC Credit Freezes and Fraud Alerts (consumer.ftc.gov)

Disclaimer: Educational only. This article does not provide tax or legal advice. Confirm current IRS reporting instructions on the source page before future material updates; do not add employee PII to reporting emails.

Published: September 11, 2026 · Last Modified: September 11, 2026 · Publisher: Blackspire Advisors · Category: Business Protection