Tax Season is a Hacker’s Dream
The “dark web” is where hackers turn to sell the valuable personal data that they have stolen from their unsuspecting victims. They sell your personal information like social security numbers, bank account details, hacked passwords, credit card account information, and even your W2 tax forms.
How do they get your W2 Form?
In the past W2 forms that have been sold on the dark web have been traced to compromises from payroll providers. Phishing emails have lead to compromises at these types of companies. But the leaks are also suspected to be from employees who have access to this data.
Data brokers on the dark web actively advertise a bounty for such information. The temptation is high when the low paid employee finds out that he or she could make a few extra thousand dollars with very low risk of getting caught. A quick copy of work data to a thumb drive is all it takes to do the breach.
Older article, current brief.
This article gives you the background. The brief gives you what changed next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
So what happens to the victims?
You will not know that anything is afoul until you file your taxes. After filing you will be notified by the IRS that your social security number was already used to file a tax return. In many cases the fraudster has already received a tax refund based on the fraudulent return. They take the money and run.
This leaves you with a bit of a mess to clean up.
First you will need to file your tax return with IRS Form 14039. This form is an Identity Theft Affidavit. The form simply tells the IRS that you are claiming that the previously filed tax return was fraudulent.
You can take heart that you are not the only one that this is happening to. The number of fraudulent tax returns are skyrocketing due to the availability of W2 and other personal information on the dark web. The IRS is dealing with thousands and thousands of fraud cases every year.
Just be patient and the system works. If you are owed a refund you certainly should not expect it quickly. After 4 weeks you can check the status of your return online. The expectation is that your refund will show up within a couple of months.
How can I avoid this type of fraud?
The best way to avoid this type of tax fraud is to file your taxes early. You want to beat the bad guys to the punch. Prepare your taxes as soon as you have the needed information and get your tax return submitted early in the cycle.
Older article, current brief.
This article gives you the background. The brief gives you what changed next.
Get the weekday cyber brief for the new exploitation, policy moves, and risk shifts this article could not cover when it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
In today’s age of stolen W2 information you have to be proactive. The fraudsters know that it is a race against time. When tax time comes they are prepped and ready to start cashing in. By filing quickly you will be able to get the jump on them and neutralize the the threat.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
Cisco Talos is making a more practical point than the headline alone suggests: if defensive workflows depend on third-party AI models that...
WordPress backup plugin flaw exposes millions of sites to takeover attacks
The All-in-One WP Migration and Backup plugin flaw is not just another WordPress plugin headline. Wordfence says CVE-2026-19949 can let an unauthenticated...
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
CVE-2026-9586 in Sangoma Switchvox is more than a generic VoIP bug. Horizon3 says the unauthenticated SQL injection in the `/pa` HTTP endpoint...
The 5-Minute Cyber Brief: September 3, 2026
The fastest way to catch up on what changed after this article was published.