The Internal Revenue Service, in partnership with the Security Summit, recently issued a warning about the growing threat of phishing scams designed to steal sensitive information. While originally intended for tax professionals, the warning is equally important for HR professionals who regularly access employee Social Security numbers, benefits information, and financial data.
Cybercriminals are increasingly targeting HR and payroll teams due to the sensitive nature of the data they manage. A single click on a suspicious link or attachment can lead to system compromise, data theft, or even ransomware attacks. As open enrollment season and year-end processes approach, the risk only increases.
Email Threats to Watch For
Hackers use several techniques to trick employees into opening dangerous emails. Here are common forms to be aware of:
Red Flags to Watch For
Steps HR Professionals Can Take to Stay Secure
The IRS and its Security Summit partners continue to encourage use of the “Security Six” practices, which apply just as effectively in HR and benefits environments:
What To Do If You Suspect a Breach
If your HR team receives a suspicious email or believes a phishing attack may have compromised data, report the incident internally and follow your organization’s security protocols. If employee tax information was involved, your team may also need to contact relevant tax authorities or your company’s legal counsel.
Cybercriminals continue to adapt. Staying informed and proactive is the best defense. Encourage your HR and payroll teams to take time this summer to review security protocols, complete required training, and be cautious with all emails and attachments.
For more information, visit the IRS’s Protect Your Clients; Protect Yourself campaign.
Benefit Allocation Systems (BAS) provides best-in-class, online solutions for: Employee Benefits Enrollment; COBRA; Flexible Spending Accounts (FSAs); Health Reimbursement Accounts (HRAs); Leave of Absence Premium Billing (LOA); Affordable Care Act Record Keeping, Compliance & IRS Reporting (ACA); Group Insurance Premium Billing; Property & Casualty Premium Billing; and Payroll Integration.
MyEnroll360 can Integrate with any insurance carrier for enrollment eligibility management (e.g., Blue Cross, Blue Shield, Aetna, United Health Care, Kaiser, CIGNA and many others), and integrate with any payroll system for enrollment deduction management (e.g., Workday, ADP, Paylocity, PayCor, UKG, and many others).
This article is for informational purposes only and is not intended as legal, tax, or benefits advice. Readers should not rely on this information for taking (or not taking) any action relating to employment, compliance, or benefits. Always consult with a qualified professional before making decisions based on this content.