Employee Identity Theft: An Employer’s Guide
Employee identity theft for employers: identity fraud at the hiring stage, your liability for staff data, the controls that stop it, and ID theft benefits.
Employee Identity Theft
Three different problems wearing the same name, and what an employer actually owes in each one
An employee once forwarded me a letter from the IRS saying that wages had been reported under his Social Security number by a company in a state he had never worked in. He was not asking me to fix it. He was asking whether it had come from us.
I could not answer that with any confidence, and the discomfort of not being able to answer is what sent me down this whole topic. It turned out that his problem and my problem were two different problems that happen to share a name, and that a third one was sitting in my hiring process where I had never thought to look.
This guide covers all three: someone working under an employee's number, someone using a stolen identity to get hired by you, and staff data walking out of your own records. It covers what you owe in each case, the controls that prevent most of it, and where identity protection fits as a benefit. Collecting sensitive employee data once and keeping it behind role-based permissions is a large part of what I built FirstHR to do. This is general information rather than legal advice.
What Employee Identity Theft Means for an Employer
Employee identity theft is the misuse of a worker's personal identifying information in a way that touches employment. For an employer it arrives from three directions, and the reason most small companies have no plan for it is that the three get discussed as if they were one thing.
Keeping them separate matters because the correct response differs completely. In the first you are a helper with useful records. In the second you are the victim of a fraud that your hiring process was supposed to catch. In the third you are the one who has to send the letter.
How It Reaches a Small Business
It reaches you through the file you are legally required to build. Onboarding a single employee collects the exact combination a criminal needs: legal name, date of birth, home address, Social Security number, bank account details, and frequently a scanned copy of a passport or driver license.
No other document set in a small company is worth as much. A customer list is worth something to a competitor. An employee record is worth money to anybody, immediately, without any knowledge of your industry, which is why the HR folder is a target out of proportion to the size of the business holding it.
Size offers no protection here, and in one respect it makes things worse. A company of twenty people typically has one person who does payroll, benefits and IT access, no separation between those roles, and no second pair of eyes on a request that looks routine.
When Someone Else Works Under Your Employee's Number
Employment-related identity theft means someone else is earning wages under your employee's Social Security number, and the employee usually learns about it from a government notice rather than from any employer. The IRS flags it with a CP01E notice, which says the number may have been used by another person for employment purposes.
The IRS is explicit that a CP01E carries no known impact on the person's tax account. It places an identity theft indicator on the account, monitors it, and recommends filing on time, getting an Identity Protection PIN, reviewing the Social Security earnings record, and considering a lock on the number. The IRS guidance on employment-related identity theft lists the other ways it surfaces: a CP2000 or CP2057 notice about income the person did not earn, or a Form W-2 arriving from an unfamiliar employer.
Your side of this is quieter and still useful. You hold the wage records that prove what the employee actually earned with you, the employment dates, and the work location. Producing those quickly, in writing, is most of what they need from you.
One caution worth stating plainly. A mismatch is not evidence about anyone's work authorization or immigration status, and treating it as if it were creates a discrimination problem on top of whatever you started with. Correct the record, ask the employee to check their own details, and keep the conversation about accuracy.
Identity Fraud at the Hiring Stage
Identity fraud at hire is the version most small employers have never considered: the person doing the job is not the person whose identity you verified. The paperwork passes because the identity itself is real, borrowed or bought from an actual person, and remote roles remove the one check that used to happen automatically, which was seeing the same face every morning.
This stopped being a theoretical risk. On June 30, 2025, the Department of Justice announced coordinated nationwide actions against schemes in which North Korean IT workers obtained remote jobs at US companies using stolen and fabricated identities, helped by facilitators inside the United States.
The uncomfortable detail is that none of the standard checks are designed to catch this. Each one answers a narrower question than employers assume it does.
| Check | What it actually verifies | What it does not catch |
|---|---|---|
| Form I-9 | That documents from the acceptable lists were presented and appear genuine and related to the person | A genuine document belonging to someone else, presented by a person who resembles the photo |
| E-Verify | That the name, date of birth and number match government records and are authorized to work | That the applicant is the person those records describe |
| E-Verify photo matching | That the photo on file matches the document shown, for four List A documents | Anything, when a different document is used or when nobody compares the faces carefully |
| Background check | History attached to the identity that was submitted | Whether the identity belongs to the applicant at all |
| Reference checks | That named people confirm the work history described | References supplied and answered by the same fraud network |
| Video interview | That a person appeared and answered | A proxy on camera, or a different person doing the job afterward |
Photo matching is the strongest of these and it is narrow. It displays the government photo on file when the employee presents one of four List A documents: the US passport, the passport card, the Permanent Resident Card and the Employment Authorization Document. It also depends entirely on a human comparing the faces rather than clicking through.
What works better is watching for the operational signals that identity checks miss. A home address that does not match the bank account name. A request to ship equipment somewhere unconnected to the employee. Reluctance to appear on camera, or a camera that behaves oddly during the hiring process. A direct deposit change in the first two weeks. None of these proves anything alone, and together they are worth a phone call before the first payroll run.
One boundary matters here. If something looks wrong, you cannot demand extra or specific documents beyond what the Form I-9 process allows, because refusing valid documents or asking for particular ones is its own violation. Verify the person through the parts of the process you control, such as a live video conversation and the address and payment details, rather than by escalating document demands.
Your Liability When Employee Data Is Stolen From You
If employee data leaks from your systems, you own the consequences on two tracks at once: statutory notification, and a common law duty of care that courts have been willing to recognize. This is the direction where employee identity theft turns into your legal problem rather than someone else's misfortune.
Notification is the first track. Every state and the District of Columbia has a breach notification law, the duty normally falls on the business that owns the data rather than the vendor holding it, and the deadline follows the affected person's state of residence. The mechanics are covered in our guide to employee data privacy, and the short version is that a vendor incident usually becomes your letter with your name at the top.
The second track is negligence. In Dittman v. UPMC, decided by the Pennsylvania Supreme Court in 2018, employees whose records were stolen sued their employer after the data was used to file fraudulent tax returns. The court recognized a duty to exercise reasonable care to safeguard employee data stored on an internet-accessible computer system, reasoning that the employer had required that data as a condition of employment.
That holding binds Pennsylvania, not the country. Treat it as the direction of travel rather than a national rule, and note the logic, which travels well: you compelled people to hand over the data, so you carry an obligation to look after it.
| Failure | How it usually happens at a small company | What it turns into |
|---|---|---|
| Bulk employee data emailed out | A message that appears to come from an owner asks payroll for copies of every W-2 | Fraudulent tax returns filed in your employees’ names, and a notification obligation |
| Access never removed | A departing employee keeps credentials to the HR or payroll system for weeks | An avoidable breach with a clear, documented failure behind it |
| Vendor incident | A payroll, benefits or screening provider is compromised | Your notification project, on your deadline, paid for by whoever your contract says |
| Documents kept forever | Scanned IDs and old background reports stay in a shared folder indefinitely | A larger blast radius and a harder conversation about why you still held it |
| Insecure disposal | Paper files or old drives discarded without shredding or wiping | A disposal rule violation, and identity data recoverable by anyone who wants it |
The last row has a specific rule behind it. Information derived from a background check run by a screening company must be disposed of under the FTC disposal rule (16 CFR 682.3), by shredding or wiping rather than recycling, so that it cannot practicably be read or reconstructed. The same standard is a sensible default for everything else in the personnel file.
The Controls That Prevent Most of It
Eight controls close nearly all of the realistic routes, and the two that matter most take an afternoon and cost nothing. This is the whole program for a business without a dedicated HR department.
Two of those are worth singling out. The bulk-data rule and the bank-detail rule together close the routes behind most employer-side incidents, and neither requires software, budget or a policy document longer than a paragraph.
The rest is mostly a consequence of where the data lives. When employee records sit in one system with role-based permissions and an audit trail, most of this list is configuration rather than discipline, which is the argument for consolidating self-service and records instead of running five disconnected tools. FirstHR is an onboarding and HR platform, not a payroll provider, so the payroll-side rules above still need to be agreed with whoever runs your pay runs.
What to Do When an Employee Reports It
Do two things in parallel: check whether your systems are the source, and make the employee's recovery easy. Those are separate jobs, and confusing them is how a supportive conversation turns into an interrogation.
The internal check is a short list. Look at their record for unauthorized changes to address or bank details, review who has opened it and when, look for any bulk export or emailed request for payroll data in the period, and confirm that nobody who left still has access. If a vendor sent you an incident notice in the same window, that is a lead rather than a coincidence.
The employee-facing half is mostly logistics. Give them their own wage records for the periods in question, written confirmation of employment dates and location, and paid time to make the calls, because every one of these organizations answers the phone during business hours only.
Self Lock deserves a note, because it is the one most people have never heard of. It sits inside a myE-Verify account, the worker-facing side of E-Verify, and places a lock on a Social Security number so that a case run by another employer returns a mismatch. The employee controls it and unlocks the number when they genuinely change jobs. The E-Verify Self Lock page explains the mechanics.
Three things not to do. Do not ask the employee to prove it with extra documents, because you are not the adjudicator here. Do not discuss it with anyone who does not need to know, since the information involved is exactly what was misused. And do not close the loop silently: tell them what you checked and what you found, even when the answer is that your systems look clean.
Write it down as it happens. The dates, the checks you ran and what you handed over are the parts you will be asked about later, and none of it is reconstructable from memory a year on.
Identity Theft Protection as an Employee Benefit
Identity theft protection is a cheap benefit that monitors credit files and identity records, alerts the employee to new activity, and provides restoration help when something goes wrong. The tax treatment is settled and favorable, which is the part most owners do not know.
IRS Announcement 2015-22 stated that the IRS will not assert that an employer providing identity protection services to employees whose information may have been compromised in a breach of the employer's recordkeeping system must include the value in employees' gross income and wages, or report it on an information return such as Form W-2. Announcement 2016-02 extended the same treatment to services provided before any breach occurs.
That second announcement is what makes this usable as an ordinary voluntary benefit rather than something you scramble to buy after an incident. Note the boundary the guidance draws: it does not cover cash paid in lieu of the services, or proceeds received under an identity theft insurance policy.
| What these services do | What they do not do | Why it matters to you |
|---|---|---|
| Monitor credit files and alert on new activity | Prevent the theft from happening | Detection speed is the variable that decides how bad it gets |
| Provide restoration specialists who do the paperwork | Make the decisions, which the employee still has to sign off on | The restoration hours are the real product, and they otherwise come out of work time |
| Often reimburse certain recovery expenses | Cover every loss automatically, since each policy sets its own limits | Read the schedule before quoting any figure to your team |
| Cover the employee, often with a family option | Protect your company records | Your systems still need the controls above, whatever the benefit says |
The honest read on adoption is that this is a low-cost, low-usage benefit. It is worth offering because the downside is small and the moment you need it, you need it immediately. If your systems were the source of a breach, offering it stops being optional in practice, whatever the law requires.
Where Employers Get This Wrong
Five patterns, and the first two account for most of the damage at companies without a dedicated HR person.
The last one is the one I got wrong. My instinct with that IRS letter was sympathy, when the useful response was a two-hour check of our own records followed by sympathy. Both are needed, and only one of them tells you whether you have a problem of your own.
Frequently Asked Questions
What is employee identity theft?
Employee identity theft is the misuse of a worker’s personal identifying information in a way that touches employment, and it arrives from three directions that share almost nothing except the name. In the first, a stranger works somewhere else under your employee’s Social Security number, which the IRS calls employment-related identity theft. In the second, an applicant is hired using an identity that belongs to someone else, so the documents check out and the person does not. In the third, staff data is stolen out of your own records, which is the only version that creates direct legal duties for the employer. Each one needs a different response, and treating them as a single problem is why most small companies have no plan for any of them.
What does it mean when the IRS tells an employee someone used their Social Security number for work?
It means the IRS has matched wages to that number that the employee did not earn, which it flags with a CP01E notice. The IRS states there is no known impact on the person’s tax account, places an identity theft indicator on it, and monitors for further activity, so this notice is informational rather than a bill. Employees may also see it as a CP2000 or CP2057 notice about unreported income, or as a Form W-2 arriving from a company they never worked for. Practical steps for the employee are to get an Identity Protection PIN, review the Social Security earnings record for wages they never earned, and consider locking the number against future employment checks. As the employer, the useful thing you hold is proof of what they actually earned with you.
Is an employer liable if employee data is stolen in a data breach?
Often yes, on two separate tracks. Every state plus the District of Columbia has a breach notification statute, and the duty to notify normally falls on the business that owns the data, which means a breach at your payroll or benefits vendor usually becomes your notification project on your deadline. Beyond notification, courts have recognized that collecting sensitive data as a condition of employment creates an obligation to protect it. In Dittman v. UPMC, the Pennsylvania Supreme Court held in 2018 that an employer has a duty to exercise reasonable care to safeguard employee data stored on an internet-accessible system, in a case where stolen records were used to file fraudulent tax returns. Read your vendor contracts for who pays notification costs before you need the answer.
Can E-Verify stop someone from being hired with a stolen identity?
No, not reliably, because E-Verify checks whether the identity is authorized to work rather than whether the applicant is that person. A real name, date of birth and Social Security number belonging to someone else will generally clear the system. Photo matching narrows the gap by displaying the government photo on file for four List A documents, the US passport, the passport card, the Permanent Resident Card and the Employment Authorization Document, so the reviewer can compare it to the document presented. That helps only when one of those four documents is used and only when a human actually compares the faces. The other half of the defense is procedural: verify the identity in a live video call, confirm the address and bank details match the person, and never let equipment ship somewhere unconnected to the employee.
What should we do if an employee tells us their identity was stolen?
Start by finding out whether your systems are implicated, then help rather than investigate. Check the employee’s record for unauthorized changes to address or bank details, review who has opened it, and look for any bulk export or emailed request for payroll data in the period. Give the employee copies of their own wage records, written confirmation of their employment dates, and paid time to make the calls, because the recovery work happens during business hours. Hand them the four routes: IdentityTheft.gov for the recovery plan, the IRS for an Identity Protection PIN, the Social Security Administration to review the earnings record, and E-Verify Self Lock to block future employment checks. Do not demand extra documents as proof, and do not discuss it with anyone who does not need to know.
Is employer-paid identity theft protection taxable to employees?
No, according to IRS guidance the value does not have to be included in employees’ gross income and wages. Announcement 2015-22 addressed identity protection services provided to employees whose information may have been compromised in a breach of the employer’s recordkeeping system, and stated that the IRS will not assert that the value belongs in gross income and wages or on an information return such as Form W-2. Announcement 2016-02 extended the same treatment to services provided before any breach happens, which is what makes this practical as an ordinary benefit rather than an apology gift. The guidance does not cover cash paid in lieu of the services or proceeds received under an identity theft insurance policy, so keep the benefit as a service.
How do we stop employee W-2 and payroll data from leaving the company?
Make bulk employee data something that never moves because an email asked for it. The recurring scam is a message that appears to come from an owner or executive asking payroll to send copies of every W-2, and it works because the request looks routine and slightly urgent. Write one rule and state it publicly so nobody feels awkward enforcing it: requests for employee tax forms, Social Security numbers or bank details are confirmed by voice on a number already on file before anything is sent, no exceptions for senior people. Pair it with the related control on the payment side, which is that direct deposit changes happen only through an authenticated self-service portal or a callback. Both cost nothing and close the two routes that account for most of this.