Cyber Incident Victim: Moneytree
Timeline
Summary
A payday lending firm experienced a data breach when an employee fell victim to a phishing scam, disclosing payroll information including names, addresses, Social Security numbers, birthdates, and W2 details for current and former U.S. staff. The attackers impersonated company leadership to obtain the sensitive data, though customer records and internal systems remained uncompromised. The incident exposed affected individuals to potential identity theft and tax refund fraud risks. In response, the company notified impacted personnel, provided financial compensation to offset credit freeze costs, and committed to strengthening organizational security practices to prevent future occurrences. This breach reflects a broader trend of W2 phishing schemes targeting businesses during tax season.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On March 4, 2016, Seattle-based financial services firm Moneytree notified current and former employees that their sensitive payroll and tax information had been compromised due to a phishing attack targeting company personnel. The incident occurred when an unidentified employee received an email request that appeared to originate from co-founder Dennis Bassford, fraudulently seeking payroll records. The employee, failing to recognize the message as fraudulent, disclosed comprehensive personal data including names, home addresses, Social Security numbers, birthdates, and W2 forms for all individuals employed by Moneytree in the United States during 2015 or hired in early 2016. Company leadership confirmed that attackers obtained this information through deception rather than technical intrusion, emphasizing that internal servers and security systems remained uncompromised and that customer records were unaffected. With over 1,200 employees according to public directory listings, the breach exposed a significant workforce to identity theft risks despite the exact notification count remaining undisclosed by company representatives contacted for verification.

The compromised data provided criminals with precisely the information required to commit tax refund fraud, a widespread scheme where thieves file falsified returns to claim illegitimate refunds. Moneytree's response included immediate employee notification via email, acknowledgment of the phishing deception's success, and a commitment to strengthen organizational information security practices. Departing from the industry standard of offering only credit monitoring services—which cannot prevent tax fraud—the company provided affected individuals with $50 in their subsequent paycheck to offset credit freeze implementation costs, a more effective identity theft deterrent. Bassford framed the incident as a learning opportunity, pledging enhanced security measures while acknowledging the responsibility to promptly disclose breaches and support impacted personnel. This incident occurred amid a surge in W2 phishing campaigns targeting businesses nationwide throughout early 2016, with numerous organizations similarly reporting employee data exposures to fraudulent tax document requests.
