“If I could sum up why I’m committed to the HR Girlfriends community it would come down to because we are ‘….in this together.'”

~Sana’ Rasul, Chief Girlfriend

Q&A: I received an email purportedly from our CEO requesting copies of employee payroll records …. Could this be a phishing scam?

Question:

I received an email purportedly from our CEO requesting copies of employee payroll records. I checked with her, and she did not send this email. Could this be a phishing scam?

Answer from Eric, SPHR, SHRM-SCP:

Yes, this is likely a phishing scam. Inform your IT staff immediately and do not respond to the email. You should also warn employees to be on the lookout for suspicious emails like this and remind them never to email sensitive employee information.

Last year, the IRS issued a warning about an emerging phishing email scheme that targets HR and payroll departments. The scammer purports to be a company executive and requests personal information about employees — often in the form of W-2s or payroll records. In other cases, they ask for a list of names, birth dates, home addresses, salaries, and social security numbers. The scammers then attempt to use the information to file fraudulent tax returns and engage in other criminal activity.

A successful scam can be a costly data breach with legal consequences for employers. For example, if an email account is hacked or accessed by an outside party, everything in the email account might be accessible to them. One of the best ways to protect your company from these sorts of scams is to have a policy and practice of never emailing sensitive employee information.

The language below may be an effective reminder:

“Employees should not under any circumstance email sensitive employee information such as W-2s, benefit enrollment forms, completed census forms, or anything with social security or credit card numbers. Email is inherently insecure, and scammers may pose as company executives or employees to steal information. If you receive a request to email any such sensitive information, do not respond to it. Instead, inform your manager immediately.”

Businesses are generally required to take reasonable precautions to protect personal information in their possession. In the event of a breach, many states require that notice is given to those whose information was compromised. This notice might need to include the cause and nature of the data breach as well as what protections are afforded to those affected.

Eric, SPHR, SHRM-SCP

Eric has extensive experience in HR, management, and training. He has held several senior HR positions, including as the HR & Operations Manager for an award-winning interactive marketing agency and as HR Director for a national law firm. Eric graduated with a Bachelor’s of Science in Economics from the University of Oregon with a minor in Business Administration.

Get Certified

The first-ever HR certification designed for professionals who are just beginning their HR career journey.

Leave a comment

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments

Are You IN?
Or Are You OUT?

It’s time you join forces with a community of like-minded peers ready to tackle the issues unique to the women of HR.

How Safe Is Your Organization?

Even with millions spent on cyber security infrastructure, all it takes is one employee clicking on one wrong link to compromise critical data, costing your company millions.

HR Girlfriends™ is a Human Resources networking organization dedicated to advancing the practice and culture of people empowerment. Our team of Girlfriends consult, train, educate, develop, share, promote, and advocate for solutions in the field of human resource management.

  • All
  • Affirmation
  • Career Mondays
  • Certification
  • COVID-19
  • CyberSAFE
  • Guest Blogger
  • HR Advisor
  • HR Law Alert
  • HR Q&A
  • HR Reading
  • HR Reel Talk
  • Join Our Team - Apply Now
  • Membership
All
  • All
  • Affirmation
  • Career Mondays
  • Certification
  • COVID-19
  • CyberSAFE
  • Guest Blogger
  • HR Advisor
  • HR Law Alert
  • HR Q&A
  • HR Reading
  • HR Reel Talk
  • Join Our Team - Apply Now
  • Membership
HR Q&A

Q&A: Can We Discipline an Employee for Not Taking a Lunch Break?

Yes, generally you can and should require an employee to take a lunch break. In many states, employers are required to provide employees with rest …

Read More →
Affirmation

Affirmation: Longevity Comes From Conscious Living

Remaining cognizant of the choices that I make is a great way to maintain lasting experiences and relationships. When I live consciously, my decisions are …

Read More →
Career Mondays

Career Monday: A Foolproof Formula For Becoming A Team Player

Unless you want to work in a lighthouse, being a team player will probably be part of your job description. It’s a question that comes …

Read More →
Share via
Copy link
Powered by Social Snap