No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Monday, October 13, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home IRS & Taxes

Expert insights on payroll data security and tax scams in 2025

by TheAdviserMagazine
7 months ago
in IRS & Taxes
Reading Time: 6 mins read
A A
Expert insights on payroll data security and tax scams in 2025
Share on FacebookShare on TwitterShare on LInkedIn


Businesses continue to face serious cyber threats that target payroll and tax information. As scams become more common, it is important for companies to protect sensitive data and stay compliant with regulations to better secure their payroll processes and reduce risks.

Cliff Steinhauer, Director of Information Security and Engagement at The National Cybersecurity Alliance (NCA), recently highlighted the importance of recognizing common payroll-related tax scams, understanding the evolution of data security threats, and leveraging advanced technology to safeguard payroll data.

He pointed out that cybercriminals are employing more sophisticated techniques, including artificial intelligence (AI) powered tools, to execute complex phishing and impersonation scams targeting payroll and business communication systems. Despite these advancements, basic security measures like multi-factor authentication remain crucial in preventing such attacks.

Vulnerabilities for payroll during tax season

Steinhauer explained that payroll departments are particularly vulnerable to scams and phishing attacks due to their involvement in money transfers and changes to employee accounting information. He noted that during the tax season, the volume of communications with employees increases, making it easier for attackers to exploit this busy period.

“[Payroll professionals] may be dealing with a lot of communications with employees during tax time if employees have questions or are asking for copies of documents or Forms W-2…or even updating…their W-4s,” Steinhauer started. He added that cybercriminals exploit the busy payroll and tax season by inserting themselves into the communication flow, taking advantage of the heightened activity and exchange of information during this period.

Techniques used by cybercriminals

Some common tactics include phishing emails and impostor emails, where attackers pose as employees or vendors to request changes to deposit information or sensitive data. Steinhauer stressed that business email compromise (BEC) is also a significant threat, where attackers use compromised email accounts or create look-alike email addresses to insert fraudulent requests into legitimate email threads.

“So, [these] types of scams are very dangerous because they’re exploiting the trust that’s built into somebody’s contact on email, which is a super common way of communicating, obviously in today’s business world,” he noted.

Steinhauer added that although this can be difficult to detect, implementing out-of-band confirmation processes and training employees to recognize suspicious emails can help mitigate the risk.

Other methods include SMS phishing (smishing) and spear phishing, targeting payroll personnel with text messages or highly targeted emails to reroute money or disclose sensitive information. Additionally, attackers are using AI to enhance phishing tactics, such as finding phishing domains, setting up fraudulent web pages, and crafting convincing emails.

“So in addition to those two or three threats, we see AI playing a part in those where it can help attackers find available phishing domains…set up fraudulent web pages that collect sensitive data…craft more convincing phishing emails…[and] proofread and rewrite emails for proper grammar and spelling,” Steinhauer remarked.

Despite these advancements, he noted that traditional security measures remain effective in mitigating these threats.

Growing scale and sophistication of cybercrime

Cybercriminal tactics are evolving and becoming more sophisticated, leading to a higher volume of attacks that are harder to detect. Steinhauer said that contrary to the image of lone hackers, these attacks are often carried out by large, organized groups with specialized skills, operating on a global scale. He noted that these groups function like businesses, with coordinated efforts and structured operations.

“The business of cybercrime continues to grow every year,” Steinhauer began. “It’s all getting higher volume and they’re now starting to use AI to…make these things better, faster, cheaper, and higher amounts of everything.”

Best practices for protecting sensitive payroll data

To enhance payroll security, Steinhauer explained that businesses can implement both technical tools and human-related training. On the technical side, email clients can flag first-time messages from unknown senders, and AI can detect common scam methods.

He said that encryption for data at rest and in transit, multi-factor authentication (MFA), and monitoring unusual activity are essential security measures.

Steinhauer added that “payroll and accounting people [are] a highly targeted group of individuals [on] the front line defense of [an] organization” who should be empowered “to make decisions and to report unusual activity” by establishing “a culture of security” that involves IT and security teams “when they see something that’s wrong.”

Training for employees to recognize and avoid payroll-related tax scams

For human training, Steinhauer stressed well-documented processes for approving changes. Employees should not be able to change direct deposit information via email alone and additional verification steps, such as phone calls or in-person ID checks, are necessary.

He added that “payroll and accounting people [are] a highly targeted group of individuals [on] the front line defense of [an] organization” who should be empowered “to make decisions and to report unusual activity” by establishing “a culture of security” that involves IT and security teams “when they see something that’s wrong.”

Some training methods Steinhauer suggested include videos, bulletins, and simulated phishing emails to help employees recognize and respond to threats. He added that an integrated security program combining technical controls and human awareness is vital for protecting payroll and other business data.

Retrospective meetings for security improvement

Just as payroll departments conduct year-end retrospectives to evaluate their processes, Steinhauer advised companies to hold regular meetings to assess data security threats. These meetings allow departments to reflect on past challenges and successes, and to plan improvements. He emphasized that including security teams in these discussions ensures that security concerns are addressed and that departments are aware of potential threats.

Pre-season security huddles

Before busy periods, such as tax season, Steinhauer also suggested companies hold pre-season huddles. “I think there’s a great opportunity to kind of have a preseason huddle with…a short presentation from the security team,” he said, adding that such a meeting can involve presenting current threats and best practices to help employees stay vigilant. He noted that this initiative-taking approach ensures everyone is prepared for potential security issues, “especially for in-person organizations.”

Proactive involvement of company departments

Steinhauer encouraged departments like payroll, HR, and accounts payable to engage with security teams to raise concerns and ask questions that helps tailor training and protection efforts to the specific needs of each department. “I think security teams and groups love to see folks raising their hands and asking questions and being inquisitive,” he said.

He added that this collaboration ensures employees understand the importance of security measures.

Connecting end users with security teams

Building strong connections between end users and security teams is important. Steinhauer admitted that these groups sometimes operate in silos, but regular communication helps both sides understand each other’s challenges. End users gain a better understanding of security controls, while security teams learn about the daily operations and needs of employees.

“And I think that a lot of folks will find that having a good relationship with your security team, and for the security team to have a good relationship with the users, really helps foster that culture of security,” Steinhauer emphasized.

The role of AI in enhancing payroll data security

Advanced technology, including AI, can play a key role in enhancing payroll data security. Steinhauer explained that detection tools analyze user interactions to establish what constitutes normal activity and alert on abnormal behavior. For example, AI can identify unusual login patterns, such as a user logging in from various locations or at unusual times.

Also, AI can analyze metadata and content to detect suspicious activities. Steinhauer said this helps identify AI-generated or phishing content by looking for language that creates urgency or deviates from company norms. Secure email tools can additionally use AI to block known phishing messages automatically.

Additionally, AI can enhance traditional security measures, making them more efficient. Steinhauer said it helps in identifying and blocking malicious activities faster than legacy tools.

Importance of basic cybersecurity protections

Although AI offers more tools to help detect tax scams and protect sensitive business data, Steinhauer highlighted the need for broader implementation of basic cybersecurity protections. He said MFA is crucial, stressing that if everyone adopted MFA, it would significantly reduce cyber-attacks. According to a NCA study Steinhauer referenced, despite its effectiveness, about 36% of users still do not use MFA.

He also noted a recent report that indicated 41% to 51% of logins on monitored websites use compromised passwords. Users often reuse passwords across different sites, increasing the risk of breaches. Steinhauer believes that awareness and encouraging users to change compromised passwords can also help mitigate this issue.

He encouraged more discussions and nudges towards these practices to enhance overall cybersecurity. “So, if I could see more…talk about that and more nudging people to implement those two things, we would go a long way towards preventing a lot of breaches,” Steinhauer advised.



Source link

Tags: dataExpertInsightsPayrollscamsSecuritytax
ShareTweetShare
Previous Post

Canada investigates whether Tesla wrongfully helped itself to a subsidy-fueled sales boom

Next Post

Is Unemployment Compensation Taxable Income?

Related Posts

edit post
The IRS Collection System is Broken – Houston Tax Attorneys

The IRS Collection System is Broken – Houston Tax Attorneys

by TheAdviserMagazine
October 12, 2025
0

Taxpayers sometimes owe the IRS and cannot currently pay. It happens. When it happens, taxpayers often reach out to the...

edit post
Guide to Tax Form 1099-SA

Guide to Tax Form 1099-SA

by TheAdviserMagazine
October 10, 2025
0

If Form 1099-SA showed up in your mailbox or inbox this year, don’t let it scare you. In this guide, we’ll break...

edit post
How to Claim Your Service Animals On Your Taxes

How to Claim Your Service Animals On Your Taxes

by TheAdviserMagazine
October 10, 2025
0

Updated for tax year 2025. Animals do more than warm our hearts — they’re road trip buddies, winter lap warmers, and sometimes,...

edit post
10 Online Tax Filing Security Tips to Protect Your Info

10 Online Tax Filing Security Tips to Protect Your Info

by TheAdviserMagazine
October 10, 2025
0

E-filing your taxes online is fast and convenient, but it also means putting sensitive personal and financial data out into...

edit post
No Tax On Overtime Explained

No Tax On Overtime Explained

by TheAdviserMagazine
October 10, 2025
0

If you’ve ever worked late nights, weekends, or double shifts, you’re likely very familiar with overtime pay. But the benefits...

edit post
Government Shutdown & Unaffordable Healthcare Subsidies

Government Shutdown & Unaffordable Healthcare Subsidies

by TheAdviserMagazine
October 10, 2025
0

The fiscal fight that resulted in the current federal government shutdown is, at its core, about the healthcare sector, spiraling...

Next Post
edit post
Is Unemployment Compensation Taxable Income?

Is Unemployment Compensation Taxable Income?

edit post
Bitcoin mining stocks down after Microsoft scraps data center plans

Bitcoin mining stocks down after Microsoft scraps data center plans

  • Trending
  • Comments
  • Latest
edit post
What Happens If a Spouse Dies Without a Will in North Carolina?

What Happens If a Spouse Dies Without a Will in North Carolina?

September 14, 2025
edit post
Pennsylvania House of Representatives Rejects Update to Child Custody Laws

Pennsylvania House of Representatives Rejects Update to Child Custody Laws

October 7, 2025
edit post
What to Do When a Loved One Dies in North Carolina

What to Do When a Loved One Dies in North Carolina

October 8, 2025
edit post
Baby Boomers Are Flocking to This Florida Town — but Not for the Weather

Baby Boomers Are Flocking to This Florida Town — but Not for the Weather

October 9, 2025
edit post
Tips to Apply for Mental Health SSDI Without Therapy

Tips to Apply for Mental Health SSDI Without Therapy

September 19, 2025
edit post
Protecting Your Parental Rights: The Risks of Three-Strike Laws in Texas Child Custody

Protecting Your Parental Rights: The Risks of Three-Strike Laws in Texas Child Custody

September 12, 2025
edit post
Sebi asks companies to give reasons, valuations for related party transactions in revised disclosures guidelines

Sebi asks companies to give reasons, valuations for related party transactions in revised disclosures guidelines

0
edit post
Flat Tax Revolution: State Income Tax Reform

Flat Tax Revolution: State Income Tax Reform

0
edit post
Bloom Energy (BE) soars on deal with Brookfield to power AI data centers

Bloom Energy (BE) soars on deal with Brookfield to power AI data centers

0
edit post
From AI FOMO to Fee Fatigue: Investor Sentiment 2025

From AI FOMO to Fee Fatigue: Investor Sentiment 2025

0
edit post
Cracker Barrel: FREE Pancakes through October 31st!

Cracker Barrel: FREE Pancakes through October 31st!

0
edit post
See It Here First at TechCrunch Disrupt 2025

See It Here First at TechCrunch Disrupt 2025

0
edit post
Cracker Barrel: FREE Pancakes through October 31st!

Cracker Barrel: FREE Pancakes through October 31st!

October 13, 2025
edit post
Jeremy Siegel says U.S. sleepwalked into rare-earths crisis as China tightens its grip

Jeremy Siegel says U.S. sleepwalked into rare-earths crisis as China tightens its grip

October 13, 2025
edit post
BNB Chain partners with Four Meme for a M reload airdrop

BNB Chain partners with Four Meme for a $45M reload airdrop

October 13, 2025
edit post
JPMorgan Launches .5 Trillion Plan to Support Industries Deemed Critical to U.S. Interests

JPMorgan Launches $1.5 Trillion Plan to Support Industries Deemed Critical to U.S. Interests

October 13, 2025
edit post
Sebi asks companies to give reasons, valuations for related party transactions in revised disclosures guidelines

Sebi asks companies to give reasons, valuations for related party transactions in revised disclosures guidelines

October 13, 2025
edit post
Bloom Energy (BE) soars on deal with Brookfield to power AI data centers

Bloom Energy (BE) soars on deal with Brookfield to power AI data centers

October 13, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Cracker Barrel: FREE Pancakes through October 31st!
  • Jeremy Siegel says U.S. sleepwalked into rare-earths crisis as China tightens its grip
  • BNB Chain partners with Four Meme for a $45M reload airdrop
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.