The Internal Revenue Service has continued to issue warnings about a prevalent phishing scam that has been circulating this tax season. The attack comes in the form of an email requesting W-2 forms or other tax information, seemingly from a valid employer or employee email address.
This same attack was used around this time last year, and now attackers are coupling it with another attack, one that requests banking information for a wire transfer – again, seemingly from an employee or employer.
“This is one of the most dangerous email phishing scams we’ve seen in a long time. It can result in the large-scale theft of sensitive data that criminals can use to commit various crimes, including filing fraudulent tax returns. We need everyone’s help to turn the tide against this scheme,’’ said IRS Commissioner John Koskinen.
The attack is what is known formally as a BEC (business email compromise) or BES (business email spoofing) attack, and it typically aims to gain access to tax or banking information for small-medium businesses through natural human error in their employees. Any business using email or online resources for their employees should provide extensive security training, which will drastically decrease the likelihood of being compromised.
A Closer Look at the Attacks
The W-2 scam is not new, appearing last year. Cyber-criminals tricked payroll and human resource officials into disclosing employee names, Social Security numbers and income information. The attackers then attempted to file fraudulent tax returns to steal tax refunds.
The spoofed emails will contain, for example, the actual name of the company chief executive officer. In this variation, the “CEO” sends an email to a company payroll office or human resource employee and requests a list of employees and information including Social Security numbers.
The following are some of the details that may be contained in the emails:
- Kindly send me the individual 2016 W-2 (PDF) and earnings summary of all W-2 of our company staff for a quick review.
- Can you send me the updated list of employees with full details (Name, Social Security Number, Date of Birth, Home Address, Salary)?
- I want you to send me the list of W-2 copy of employee’s wages and tax statements for 2016, I need them in PDF file type, you can send it as an attachment. Kindly prepare the lists and email them to me asap.
New Attack: The Money Wire Request
In the latest addition to the W-2 scam, the cyber-criminal follows up with an “executive” email to the payroll or HR staff and asks that a wire transfer also be made to a certain account. Although not tax related, the wire transfer scam is being coupled with the W-2 scam email, and some companies have lost both employees’ W-2s and thousands of dollars due to wire transfers.
While the money wire request is not a new attack, seeing it coupled with the W-2 attack is what makes it even more important that both employers and employees remain vigilant. The wire request may not come for weeks or even months after the W-2 attack.
What You can Do
As mentioned above, the single most important thing you can do if you’re an employer is ensure that all your employees have adequate online security training. In addition, if you work with any databases or online interactions whatsoever within your company, you need to ensure that your building and network are both physically and digitally secure.
If you aren’t an employer, you should at least read our 10 tips on making the internet a safer place!
From our perspective, 2016 was an incredible year for us. We felt that not only in our tremendous growth as a company, but also in the connections we made with, and the overall feedback we got from, our valued merchants and members. With over 100,000 connections through our customer support, and more still through our blog and social media, plus millions of transactions on our website, we have a pretty solid picture of how we’ve grown and improved our services over the past year.
As many will know, we have quite a long history in the online payment processing and eWallet industries. We’re not perfect, we’ve had to learn from our mistakes and value every bit of feedback we’ve gotten over the past 10+ years. But one thing we have noticed lately is that we are seeing much less negative feedback, especially around the web. But we want to know what we can do to foster positive feedback and, most importantly, continue to improve our service to you.
We’ve made a real effort to listen and respond to your valued feedback in the past, and we believe that has been to great effect for everyone. Now, we’d like to continue that relationship by asking for your feedback again.
(click above to help us out by leaving a review on sitejabber.com)
(click above, or leave your feedback on our Facebook page, or send it to email@example.com)
Additional ways to help below
- Leave a review of SolidTrust Pay on TrustPilot.com
- Leave a review of SolidTrust Pay at the BBB
- Leave a review on our Facebook Page
With 2017 barreling in and 2016 a fading memory, we wanted to take one last look back at our year and share with our members some of the memories we have. We learned new ways to connect with you and celebrated our ten year anniversary, which coincided with our member appreciation week. We saw tremendous growth with our valued merchants and loyal members, and we finished the year strong thanks to our fantastic group of dedicated employees!
Our Facebook Christmas Contest was a great experience, and a great way to learn about some of our members. We connected with many of you, and were able to help out some great people along the way. We want to do more things like this in the future! Lets see what some of our winners had to say.
Wow ! What a pleasant surprise, and I can only say with a grateful heart that God is good all the time, and all the time God is good! Thank you SolidTrust Pay for your prompt and efficient service, and for your heart to help everyone in need. Thank you also for the prize!
Best wishes and God Bless,
Thank you very much, this is a really nice Christmas gift and a really good feeling to donate something to World Vision that will help a mother and a baby in need.Best regards, Marry Christmas and Happy New Year,
We gave $500 to 5 randomly chosen members who signed up for the contest, and then we gave them $500 to purchase donation packages from World Vision. With our added contribution, we were able to fully stock two medical clinics, build and properly install two latrines, and send much needed food, baby care and school supplies to communities affected by poverty and war. Click the World Vision logo if you’re able to help as well.
We Started Working With Transpay!
We made a significant decision to partner with Transpay to offer our members an option that’s cheaper than a traditional wire and faster than an ACH. We released an extensive guide with a video tutorial for this option so that everybody will be able to take advantage of this exciting new way to pay!
On June 15, 2016, SolidTrust Pay became ten years old! We celebrated with a contest similar to our Facebook contest, and had more great chances to connect with our members. This was during our Member Appreciation Week, and we’re excited to do it again this year!
SolidTrust Pay Growth in 2016
In the last quarter of 2016, we saw an explosion of payment button requests from merchants and entrepreneurs looking to find the best payment processor for 2017. With so many merchant service requests, we saw our daily user signups double in Q4! This is why we value our merchants so much; it’s also what keeps our customer support, payments and verification staff working so hard to stay on top of it all! That being said, it’s you, our members, who we owe everything to. Thank you all!
We Rode the Bitcoin Roller-Coaster
We continued to allow users to deposit from their bitcoin wallets into their STP wallets, having their BTC converted to USD automatically and then having the option to spend, exchange or withdraw it directly into their bank accounts. We also continued to offer our payment button services to merchants who want to accept bitcoin directly on their websites. All this, in spite of the volatility of BTC towards the end of 2016, made for some pretty trying times!
We look forward to growing with the blockchain over 2017 though. Many of our members love the option to buy, exchange and withdraw bitcoin, so it’s not going anywhere any time soon!
Looking Toward the Future and 2017
Looking back, we’re nothing but happy and grateful for the year that we had. Looking into the future, we want to make sure we continue to grow as a company, but also as a community. Many of our merchants bring entire communities to our doorstep, and we would be remiss if we did not take the opportunity to join those communities, and also to build our own. Follow us on Facebook and Twitter @solidtrustpay to keep up with us!
In addition to major site updates to SolidtrustPay.com, we aim to reach out and connect more with both our existing members, and the industry at large. We have more chances to win cash prizes through Facebook and social media contests planned, updates to the site that will bring you closer to your digital wallet, and a few other surprises to that will keep SolidTrust Pay on the cutting edge of the online payment processing industry, and the preferred eWallet of millions of users worldwide!
SolidTrust Pay is dedicated to maintaining a competitive place in the online payment processing industry. We love to build relationships with our daily users and members, as well as our merchants through our timely customer support and social media interactions. We take our role in helping you facilitate your online money transactions very seriously!
With many recent and unexpected changes for merchants and business owners in the online industry, we feel it is our duty to provide you with an easy place to find all the best information to help you compare SolidTrust Pay with the competition! In this article, we’re going to go over the differences that matter to you as an online merchant, including the fees, security, customer service and reliability you can expect from us.
Fees at SolidTrust Pay
SolidTrust Pay has an incredibly diverse, accommodating and comprehensive platform for payment processing. We offer you a variety of tools and options to help manage your money online and run your eCommerce business seamlessly. With many different options for withdrawals, transfers, payments and deposits, it’s only fair that our fees are made specific to which type of transaction you are making. This way, it’s easy for you to determine a method of running your operations that is suitable to your needs. So, at SolidTrust Pay, our customer support team is happy to help you find the best methods of transaction for whatever your industry and business model.
As a point of reference, you may have heard that there are 4 pricing models for the payment processing industry:
- Interchange Plus
You can get the full picture of what these terms mean and the differences between them by reading Merchant Maverick’s great article on the topic, but all you need to know for the purpose of this article is that SolidTrust Pay doesn’t operate strictly under any of these models. We know that each model isn’t perfect, and that in many cases a level of customization may be required to make the situation work for the customer or merchant using our services. Many new business models, such as the paid-to-click model and various Bitcoin innovations, fall into that category. Our Micro Payments upgrade for business accounts is a perfect example of this, when we created an option to lower your processing fee to just $0.05 per transaction, while modestly increasing the percentage fee from 2.5% to 5%. This makes a huge difference when you’re doing a lot of small transactions, and so we offer it to all members with business accounts!
That being said, where the industry-average processing fee is 2.9% +$0.30 per transaction, we’re confident that our pricing starting at 1.5% +$0.25 for personal accounts and 2.5% +$0.35 for business accounts will remain the fairest in the industry. Take a look at our business account fees and benefits, as well as our personal account fees and benefits, and compare them with our competition!
Security at SolidTrust Pay
We feel at SolidTrust Pay that security is absolutely the most important aspect of running any online business. We apply a plethora of security measures to all money transactions, account registration and access, and handling of personal/confidential information. We operate in compliance with all regulatory bodies relevant to our industry, and we employ strategies developed within SolidTrust Pay to work endlessly to reduce the amount of security risks, hacking, fraud and credit card chargebacks experienced on our systems.
Customer Support & Reliability at SolidTrust Pay
We’re a family-owned and operated company located in the heart of Canada – to say we’re a pleasant bunch is an understatement! We absolutely love to help our members better understand our platform and more easily use it, that’s why we have a live chat system as well as a ticket support system for when chat is offline! Our dedicated customer support team is waiting to answer any questions you might have via chat or ticket, but we also encourage you to reach out to us via social media, and follow our Facebook/Twitter accounts for up-the-the-minute news and updates. We’re really looking forward to working with you!