No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Thursday, September 18, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home IRS & Taxes

Expert insights on payroll data security and tax scams in 2025

by TheAdviserMagazine
6 months ago
in IRS & Taxes
Reading Time: 6 mins read
A A
Expert insights on payroll data security and tax scams in 2025
Share on FacebookShare on TwitterShare on LInkedIn


Businesses continue to face serious cyber threats that target payroll and tax information. As scams become more common, it is important for companies to protect sensitive data and stay compliant with regulations to better secure their payroll processes and reduce risks.

Cliff Steinhauer, Director of Information Security and Engagement at The National Cybersecurity Alliance (NCA), recently highlighted the importance of recognizing common payroll-related tax scams, understanding the evolution of data security threats, and leveraging advanced technology to safeguard payroll data.

He pointed out that cybercriminals are employing more sophisticated techniques, including artificial intelligence (AI) powered tools, to execute complex phishing and impersonation scams targeting payroll and business communication systems. Despite these advancements, basic security measures like multi-factor authentication remain crucial in preventing such attacks.

Vulnerabilities for payroll during tax season

Steinhauer explained that payroll departments are particularly vulnerable to scams and phishing attacks due to their involvement in money transfers and changes to employee accounting information. He noted that during the tax season, the volume of communications with employees increases, making it easier for attackers to exploit this busy period.

“[Payroll professionals] may be dealing with a lot of communications with employees during tax time if employees have questions or are asking for copies of documents or Forms W-2…or even updating…their W-4s,” Steinhauer started. He added that cybercriminals exploit the busy payroll and tax season by inserting themselves into the communication flow, taking advantage of the heightened activity and exchange of information during this period.

Techniques used by cybercriminals

Some common tactics include phishing emails and impostor emails, where attackers pose as employees or vendors to request changes to deposit information or sensitive data. Steinhauer stressed that business email compromise (BEC) is also a significant threat, where attackers use compromised email accounts or create look-alike email addresses to insert fraudulent requests into legitimate email threads.

“So, [these] types of scams are very dangerous because they’re exploiting the trust that’s built into somebody’s contact on email, which is a super common way of communicating, obviously in today’s business world,” he noted.

Steinhauer added that although this can be difficult to detect, implementing out-of-band confirmation processes and training employees to recognize suspicious emails can help mitigate the risk.

Other methods include SMS phishing (smishing) and spear phishing, targeting payroll personnel with text messages or highly targeted emails to reroute money or disclose sensitive information. Additionally, attackers are using AI to enhance phishing tactics, such as finding phishing domains, setting up fraudulent web pages, and crafting convincing emails.

“So in addition to those two or three threats, we see AI playing a part in those where it can help attackers find available phishing domains…set up fraudulent web pages that collect sensitive data…craft more convincing phishing emails…[and] proofread and rewrite emails for proper grammar and spelling,” Steinhauer remarked.

Despite these advancements, he noted that traditional security measures remain effective in mitigating these threats.

Growing scale and sophistication of cybercrime

Cybercriminal tactics are evolving and becoming more sophisticated, leading to a higher volume of attacks that are harder to detect. Steinhauer said that contrary to the image of lone hackers, these attacks are often carried out by large, organized groups with specialized skills, operating on a global scale. He noted that these groups function like businesses, with coordinated efforts and structured operations.

“The business of cybercrime continues to grow every year,” Steinhauer began. “It’s all getting higher volume and they’re now starting to use AI to…make these things better, faster, cheaper, and higher amounts of everything.”

Best practices for protecting sensitive payroll data

To enhance payroll security, Steinhauer explained that businesses can implement both technical tools and human-related training. On the technical side, email clients can flag first-time messages from unknown senders, and AI can detect common scam methods.

He said that encryption for data at rest and in transit, multi-factor authentication (MFA), and monitoring unusual activity are essential security measures.

Steinhauer added that “payroll and accounting people [are] a highly targeted group of individuals [on] the front line defense of [an] organization” who should be empowered “to make decisions and to report unusual activity” by establishing “a culture of security” that involves IT and security teams “when they see something that’s wrong.”

Training for employees to recognize and avoid payroll-related tax scams

For human training, Steinhauer stressed well-documented processes for approving changes. Employees should not be able to change direct deposit information via email alone and additional verification steps, such as phone calls or in-person ID checks, are necessary.

He added that “payroll and accounting people [are] a highly targeted group of individuals [on] the front line defense of [an] organization” who should be empowered “to make decisions and to report unusual activity” by establishing “a culture of security” that involves IT and security teams “when they see something that’s wrong.”

Some training methods Steinhauer suggested include videos, bulletins, and simulated phishing emails to help employees recognize and respond to threats. He added that an integrated security program combining technical controls and human awareness is vital for protecting payroll and other business data.

Retrospective meetings for security improvement

Just as payroll departments conduct year-end retrospectives to evaluate their processes, Steinhauer advised companies to hold regular meetings to assess data security threats. These meetings allow departments to reflect on past challenges and successes, and to plan improvements. He emphasized that including security teams in these discussions ensures that security concerns are addressed and that departments are aware of potential threats.

Pre-season security huddles

Before busy periods, such as tax season, Steinhauer also suggested companies hold pre-season huddles. “I think there’s a great opportunity to kind of have a preseason huddle with…a short presentation from the security team,” he said, adding that such a meeting can involve presenting current threats and best practices to help employees stay vigilant. He noted that this initiative-taking approach ensures everyone is prepared for potential security issues, “especially for in-person organizations.”

Proactive involvement of company departments

Steinhauer encouraged departments like payroll, HR, and accounts payable to engage with security teams to raise concerns and ask questions that helps tailor training and protection efforts to the specific needs of each department. “I think security teams and groups love to see folks raising their hands and asking questions and being inquisitive,” he said.

He added that this collaboration ensures employees understand the importance of security measures.

Connecting end users with security teams

Building strong connections between end users and security teams is important. Steinhauer admitted that these groups sometimes operate in silos, but regular communication helps both sides understand each other’s challenges. End users gain a better understanding of security controls, while security teams learn about the daily operations and needs of employees.

“And I think that a lot of folks will find that having a good relationship with your security team, and for the security team to have a good relationship with the users, really helps foster that culture of security,” Steinhauer emphasized.

The role of AI in enhancing payroll data security

Advanced technology, including AI, can play a key role in enhancing payroll data security. Steinhauer explained that detection tools analyze user interactions to establish what constitutes normal activity and alert on abnormal behavior. For example, AI can identify unusual login patterns, such as a user logging in from various locations or at unusual times.

Also, AI can analyze metadata and content to detect suspicious activities. Steinhauer said this helps identify AI-generated or phishing content by looking for language that creates urgency or deviates from company norms. Secure email tools can additionally use AI to block known phishing messages automatically.

Additionally, AI can enhance traditional security measures, making them more efficient. Steinhauer said it helps in identifying and blocking malicious activities faster than legacy tools.

Importance of basic cybersecurity protections

Although AI offers more tools to help detect tax scams and protect sensitive business data, Steinhauer highlighted the need for broader implementation of basic cybersecurity protections. He said MFA is crucial, stressing that if everyone adopted MFA, it would significantly reduce cyber-attacks. According to a NCA study Steinhauer referenced, despite its effectiveness, about 36% of users still do not use MFA.

He also noted a recent report that indicated 41% to 51% of logins on monitored websites use compromised passwords. Users often reuse passwords across different sites, increasing the risk of breaches. Steinhauer believes that awareness and encouraging users to change compromised passwords can also help mitigate this issue.

He encouraged more discussions and nudges towards these practices to enhance overall cybersecurity. “So, if I could see more…talk about that and more nudging people to implement those two things, we would go a long way towards preventing a lot of breaches,” Steinhauer advised.



Source link

Tags: dataExpertInsightsPayrollscamsSecuritytax
ShareTweetShare
Previous Post

Canada investigates whether Tesla wrongfully helped itself to a subsidy-fueled sales boom

Next Post

Is Unemployment Compensation Taxable Income?

Related Posts

edit post
A Pathway to Professional Freedom: The Case for Simplicity

A Pathway to Professional Freedom: The Case for Simplicity

by TheAdviserMagazine
September 17, 2025
0

The Wake-Up Call We Didn’t Expect  When COVID arrived, it forced firms everywhere into an unplanned experiment. Overnight, offices shut...

edit post
Canopy Smart Intake Expands to Include AI-Driven Document Requests

Canopy Smart Intake Expands to Include AI-Driven Document Requests

by TheAdviserMagazine
September 16, 2025
0

Create a custom request list in seconds with information already in Canopy SALT LAKE CITY –September 16, 2025 – Canopy,...

edit post
How AI is affecting accounting advisory

How AI is affecting accounting advisory

by TheAdviserMagazine
September 16, 2025
0

While many firms are still debating whether to adopt AI, their clients have already moved past the question of if — and...

edit post
Common LLC Errors That Put Rental Property Owners at Risk |

Common LLC Errors That Put Rental Property Owners at Risk |

by TheAdviserMagazine
September 16, 2025
0

Why LLC Mistakes Matter Many real estate investors create an LLC for asset protection, thinking the work is done. But...

edit post
Online Sports Betting Taxes, 2025

Online Sports Betting Taxes, 2025

by TheAdviserMagazine
September 16, 2025
0

Significant Changes Since January 1, 2024 Delaware began legal online sports gambling operations with a 50 percent tax rate, the...

edit post
Automated Investing Made Simple | Intuit TurboTax Blog

Automated Investing Made Simple | Intuit TurboTax Blog

by TheAdviserMagazine
September 15, 2025
0

Automated investing can be a simple way to build wealth without overthinking it. By setting up recurring contributions to accounts...

Next Post
edit post
Is Unemployment Compensation Taxable Income?

Is Unemployment Compensation Taxable Income?

edit post
Bitcoin mining stocks down after Microsoft scraps data center plans

Bitcoin mining stocks down after Microsoft scraps data center plans

  • Trending
  • Comments
  • Latest
edit post
What Happens If a Spouse Dies Without a Will in North Carolina?

What Happens If a Spouse Dies Without a Will in North Carolina?

September 14, 2025
edit post
California May Reimplement Mask Mandates

California May Reimplement Mask Mandates

September 5, 2025
edit post
Who Needs a Trust Instead of a Will in North Carolina?

Who Needs a Trust Instead of a Will in North Carolina?

September 1, 2025
edit post
Does a Will Need to Be Notarized in North Carolina?

Does a Will Need to Be Notarized in North Carolina?

September 8, 2025
edit post
DACA recipients no longer eligible for Marketplace health insurance and subsidies

DACA recipients no longer eligible for Marketplace health insurance and subsidies

September 11, 2025
edit post
Big Dave’s Cheesesteaks CEO grew up in ‘survival mode’ selling newspapers and bean pies—now his chain sells a  cheesesteak every 58 seconds

Big Dave’s Cheesesteaks CEO grew up in ‘survival mode’ selling newspapers and bean pies—now his chain sells a $12 cheesesteak every 58 seconds

August 30, 2025
edit post
Block, Inc. (XYZ): A Bull Case Theory

Block, Inc. (XYZ): A Bull Case Theory

0
edit post
Why Data Beats Depreciation Every Time

Why Data Beats Depreciation Every Time

0
edit post
Jobs report revisions September 2025:

Jobs report revisions September 2025:

0
edit post
XRP Bulls Poised – .12 Break Might Start Strong Upswing

XRP Bulls Poised – $3.12 Break Might Start Strong Upswing

0
edit post
Could Energy Upgrades Pay Back Faster Than Your Bond Fund?

Could Energy Upgrades Pay Back Faster Than Your Bond Fund?

0
edit post
How connected is your firm’s tech

How connected is your firm’s tech

0
edit post
XRP Bulls Poised – .12 Break Might Start Strong Upswing

XRP Bulls Poised – $3.12 Break Might Start Strong Upswing

September 18, 2025
edit post
India’s Goldilocks mix of high growth and low inflation is sustainable in the short term: LGT Wealth

India’s Goldilocks mix of high growth and low inflation is sustainable in the short term: LGT Wealth

September 17, 2025
edit post
Amazon to invest over  billion in fulfillment and transportation workers to boost pay

Amazon to invest over $1 billion in fulfillment and transportation workers to boost pay

September 17, 2025
edit post
Citi Predicts ETH at ,300 by End of 2025, Citing Investor Optimism Over Activity

Citi Predicts ETH at $4,300 by End of 2025, Citing Investor Optimism Over Activity

September 17, 2025
edit post
Small Leaks, Big Impact: How Tiny Daily Spending Habits Can Quietly Drain (or Transform!) Your Budget

Small Leaks, Big Impact: How Tiny Daily Spending Habits Can Quietly Drain (or Transform!) Your Budget

September 17, 2025
edit post
Nvidia AI chip challenger Groq raises even more than expected, hits .9B valuation

Nvidia AI chip challenger Groq raises even more than expected, hits $6.9B valuation

September 17, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • XRP Bulls Poised – $3.12 Break Might Start Strong Upswing
  • India’s Goldilocks mix of high growth and low inflation is sustainable in the short term: LGT Wealth
  • Amazon to invest over $1 billion in fulfillment and transportation workers to boost pay
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.