Verifying a request
The one habit that stops most social engineering: before you send data, change bank details or move money, confirm the request through a channel you already trust.
Scams work because the message looks real. A hijacked email account sends from the right address, and a spoofed one comes close enough. So the test cannot be "does this look genuine?" The test is "have I confirmed this somewhere the scammer cannot reach?"
Call back on a number you already have
When a request is unusual, contact the person a different way from the way the request arrived:
- Use the phone number already in the client's file, the vendor's contract, or an official website you type in yourself.
- Never use the phone number, link or reply address in the message itself. If the message is fake, those lead straight back to the scammer.
- A reply to the same email thread proves nothing. If the account is compromised, the scammer answers.
The IRS gives the same advice for unknown senders, including people who say they are prospective clients: make contact first, by phone for example, before opening anything they send.
Requests that always get a call back
- Changing refund or bank details. Never change where a refund is deposited, or where the firm sends money, on the strength of an email or text alone. The IRS advises a final review of return information before e-filing, especially direct deposit details.
- W-2s, payroll lists, client lists or Social Security numbers, even when the request appears to come from a partner, an executive or the client. The IRS describes W-2 scams that impersonate an organization's own executive.
- Paying a new account, or paying urgently.
- Passwords, sign-in codes or remote access to your computer. No genuine colleague, vendor or client needs your sign-in code.
- Anything from "the IRS" that arrives by email, text, social media or a threatening call. The IRS says it normally makes first contact by mail. See For your clients for the full list of what the IRS does and does not do.
Urgency and authority are the tell
Scammers rarely give you time to think. The IRS notes that phishing emails usually have an urgent subject line, and that threats of arrest are a common scam tactic. Threats of sudden penalties or account closures work the same way. W-2 scams borrow the authority of a senior person so that questioning the request feels awkward.
A few things help:
- Make verifying the rule, not a personal choice. Write it into your firm's procedures: certain requests are always confirmed by phone, no matter who asks. Then nobody has to decide in the moment whether it is rude to check.
- Say out loud that no one gets in trouble for checking. A partner who is annoyed by a two-minute call is far cheaper than a breach.
- Route requests for client information to people who know the procedure. The FTC's guidance, as reproduced in the IRS's guide for tax professionals, suggests referring requests for customer information to designated staff trained in how the firm protects personal data, and reporting suspicious attempts to them.
- Slow down on purpose when a message says "now". Real deadlines survive a phone call.
A short script
"Thanks, I got your email about changing the deposit account. Before I make any change I always confirm by phone. I'm calling the number we have on file for you. Did you send that request?"
If the answer is no, you have just stopped a fraud. Tell your security lead, and if a client's email account appears to be compromised, let the client know by phone.
How Journey helps
- The audit log shows who changed what. Owners and General Managers can open Settings, then Audit log, to see changes to clients, returns and requests, invoices, staff and tasks, with who made each change and when. If a client's details changed and nobody remembers doing it, that is where to look.
- Staff sign-in needs more than a password. Signing in to Journey asks staff for a code from their authenticator app as well as the password.
Sources
- IRS Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024), sections "Take Basic Security Steps", "Recognize Phishing Scams", "Guard Against Phishing Emails" and "Employee Management and Training": irs.gov/pub/irs-pdf/p4557.pdf
- IRS, "Form W-2/SSN data theft: Information for businesses and payroll service providers": irs.gov
- IRS, "How to know it's really the IRS calling or knocking on your door" (FS-2017-7): irs.gov
- IRS, "How to know it's the IRS": irs.gov/help/how-to-know-its-the-irs