From would-be Nigerian princes to foreign lottery officials, cybercriminals have been known to assume all sorts of false identities to carry out email phishing scams that trick unsuspecting consumers into clicking on fraudulent links or divulging personal information to strangers. We often see a spike in this type of activity around tax season, when fraudsters target taxpayers in an attempt to make off with their refunds. This year, however, the annual spike is looking more like an epidemic as a variant affecting human resources departments has begun to spread with a vengeance.
On March 1, 2016, the IRS issued an alert warning “payroll and human resources professionals to beware of an emerging phishing email scheme that purports to be from company executives and requests personal information on employees.” Less than a week later, on March 7, the Attorney General of North Carolina sounded a similar alarm concerning the rise in phishing-related breaches, reporting that “[i]n 2016, 26 phishing breaches have been reported by businesses and other organizations with 16 of those reports coming within the past two weeks, compared to eight phishing breaches reported in all of 2015.”