Situation

Your employer notifies you that its payroll provider or HR system was breached, and W-2 or Social Security number data may have been exposed.

Why a payroll breach is different from a general SSN exposure

Plenty of breaches expose a Social Security number on its own. A payroll or W-2 breach exposes it bundled with your wage information, your employer's name, and often your full legal name and address in one record — the exact combination a fraudulent tax return needs. That makes this specific kind of breach unusually well suited to tax refund fraud, which is why the IRS treats W-2 data theft as its own category with its own reporting channel.

The employer notice you received will typically say whether the exposure was limited to employee records used for payroll (name, SSN, wage amounts) or extended further into other HR data like bank account numbers for direct deposit, benefits elections, or dates of birth.

What your employer is required to do

If your employer's own payroll data — or a payroll vendor's system holding your employer's data — is breached, the business is expected to report the loss to the IRS by emailing dataloss@irs.gov, providing details so the IRS can flag affected Social Security numbers for extra tax-fraud screening. This is separate from any state breach-notification letter you receive as an employee.

Ask your employer's HR department directly whether this IRS notification was made, and when. It doesn't remove your own risk, but it tells you whether the IRS already has advance warning to watch your SSN specifically.

Get an IRS Identity Protection PIN

An Identity Protection PIN is a six-digit number the IRS requires on any tax return filed under your Social Security number, whether paper or electronic. Without the correct current-year PIN, a return — including a fraudulent one — is rejected. Any taxpayer can request one voluntarily through the IRS's online tool, and it is the single most direct defense against a fraudulent return filed with a stolen W-2/SSN combination.

If you already had a PIN from a previous year, note that a new one is issued each filing season — check that you're using the current year's number when tax season arrives, not last year's.

File your real return as early as you reasonably can

Fraudulent returns filed with a stolen SSN are typically submitted early in filing season specifically to beat the real taxpayer to the refund. If your real return is already on file with the IRS by the time a fraudulent one is attempted, the fraudulent one is rejected as a duplicate rather than the other way around.

You don't need to rush a return you're not ready to file, but if a W-2/SSN breach happened close to tax season, treat early, accurate filing as a genuine defensive measure rather than just a convenience.

If a fraudulent return has already been filed

If you try to e-file and it's rejected because a return already exists for your Social Security number for that tax year, that's the signature sign of tax identity theft. File Form 14039, the Identity Theft Affidavit, with the IRS, and continue to file your real return on paper alongside it if e-filing continues to be blocked.

This is a different form from Form 14039-B, which is for a business reporting theft of its own Employer Identification Number — as an individual employee responding to your own SSN being misused, Form 14039 is the correct one.

Watch for wage-related identity theft beyond your own tax return

A stolen SSN and wage profile can also be used to claim unemployment benefits in your name, or to gain employment elsewhere using your identity — which can show up years later as a mismatch when the Social Security Administration records wages from an employer you never worked for. If you later notice unemployment benefits filed in your name, or a Social Security earnings statement listing wages from a job you didn't hold, treat those as delayed consequences of the same original W-2 breach.

Standard breach steps still apply

Beyond the tax-specific steps, treat this like any breach that exposed a Social Security number: freeze your credit at all three nationwide bureaus, since the SSN alone (regardless of the payroll context) can also be used to open new credit accounts unrelated to taxes.

Frequently asked questions about payroll and W-2 breaches

  • Is my employer liable if their payroll vendor gets breached? That depends on the contract between your employer and the vendor and on applicable state law — as an employee, your practical concern is your own SSN exposure, not the liability question between the two businesses.
  • Should I ask for a new Social Security number? The Social Security Administration only issues a new number in narrow, documented cases of ongoing serious harm, and a single payroll breach on its own is unlikely to meet that bar — an Identity Protection PIN and early filing address the tax-fraud risk without needing a new SSN.
  • How long does the fraud risk from a W-2 breach last? Longer than a typical financial breach — a Social Security number doesn't expire, so watch for tax-related fraud not just in the immediate next filing season but in subsequent years too, since stolen SSN/wage data can be held and used later.
  • Does an Identity Protection PIN protect against anything besides tax fraud? No — it specifically blocks fraudulent tax return filing under your SSN. It does nothing to prevent new credit accounts being opened in your name, which is why a credit freeze is still a separate, necessary step for the same underlying SSN exposure.

A W-2 phishing breach discovered in February

Your employer emails staff in February to say someone impersonating an executive tricked a payroll employee into emailing a spreadsheet of every employee's W-2 information to an outside address — a well-documented and common way these breaches happen, distinct from a technical hack.

Because it's still early in tax season, you request an Identity Protection PIN immediately and file your own return within the next few weeks rather than waiting until the usual deadline. You also freeze your credit at all three bureaus the same week, since your SSN was exposed regardless of the tax angle, and you ask HR to confirm whether they've reported the loss to the IRS.

Primary sources used

Check the official source before you submit sensitive information.