Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Experian handling 70 breaches a week resulting from IRS phishing scam

By Brian Wheelin on April 13, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

On March 1, 2016, the Internal Revenue Service alerted the business community of an e-mail phishing scheme designed to convince employees to provide company-wide W-2 tax forms containing social security numbers and other personally identifiable information [view related post].  While the scam has taken different forms, the most prevalent approach is a purported internal e-mail from a company’s CEO or CFO to his/her payroll and/or human resource employees requesting all issued W-2s.

While the IRS warning noted that the scam already resulted in “several victims,” the phishing efforts are, unfortunately, working on a much larger scale.   The director of Experian’s data breach resolution group stated earlier this month that the information services company is handling more than 70 data breaches a week resulting from this one type of phishing scam.  Perhaps this number is not too surprising when one considers the 100 billion spam e-mails sent daily.

Incidents of employee negligence continue to be one of the primary causes of data breaches suffered by companies both big and small.    Companies may want to strongly consider implementing proactive measures designed at reducing the likelihood of breaches.    This could include appropriate employee training, monitoring and advising employees of recent phishing trends and installing appropriate software designed to block spam e-mails before they hit employee inboxes.   Businesses may also contemplate establishing programs designate to reward employees who report potential attacks as opposed to punishing employees who mistakenly respond to a phishing e-mail.

Photo of Brian Wheelin Brian Wheelin

Brian Wheelin is a member of the firm’s Business Litigation Group, where he focuses his practice on complex commercial litigation, including privacy and cybersecurity matters.

Brian has first-chaired cases to verdict as well as argued appeals before the United States Second Circuit and…

Brian Wheelin is a member of the firm’s Business Litigation Group, where he focuses his practice on complex commercial litigation, including privacy and cybersecurity matters.

Brian has first-chaired cases to verdict as well as argued appeals before the United States Second Circuit and state appellate courts in Connecticut and New York. He represents both individuals and companies in commercial litigation matters encompassing business torts, contract breaches, and disputes related to employment, real estate, and intellectual property.

Brian serves on the firm’s Electronic Discovery Committee. Read his full rc.com bio here.

Read more about Brian WheelinEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo