Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Public Library of Science Data Breach

On February 3, 2026, Public Library of Science (PLOS) experienced a spear-phishing attack that resulted in 2025 W-2 forms being sent to an unauthorized third party. The exposed information includes Social Security numbers and tax data. Affected employees should take immediate protective steps

Public Library of Science
Date of Breach: February 3, 2026
CAU logo

Who was affected:

Clients of Public Library of Science

Impacted Data:

Name

Residential address

Social Security number

Salary information

Tax withholding information

Public Library of Science (“PLOS”) recently disclosed a data breach after a spear-phishing attack led to the unauthorized disclosure of employee W-2 forms. The incident occurred on February 3, 2026, and exposed highly sensitive personal and tax-related information.

Public Library of Science’s Data Breach Investigation

On February 3, 2026, PLOS discovered that it had been the victim of a spear-phishing attack. According to the notice, a phishing email was mistakenly responded to, resulting in copies of U.S. employees’ 2025 W-2 tax forms being sent to an unknown third party.

The incident was reported immediately upon discovery, and PLOS began investigating the same day. The organization also contacted appropriate law enforcement authorities, including the Internal Revenue Service (IRS) and the Federal Bureau of Investigation (FBI). Following the report to the IRS, the agency initiated a risk assessment that may include monitoring affected taxpayer accounts for signs of identity theft.

The compromised W-2 forms include extremely sensitive personal information, such as:

  • Name

  • Residential address

  • Social Security number

  • Salary information

  • Tax withholding information

Although PLOS maintains other employment-related information, including bank account details used for payroll and direct deposit, the organization stated that only the information contained in the 2025 W-2 forms was affected. Bank account information was not compromised in this incident.

Spear-phishing attacks are a targeted form of phishing in which attackers impersonate trusted individuals or entities to trick recipients into disclosing sensitive information. W-2 phishing scams are particularly dangerous because they can lead to fraudulent tax filings and identity theft.

PLOS stated that it is not currently aware of any improper use of the disclosed information. However, similar attacks have historically resulted in fraudulent tax returns being filed in victims’ names, often before the victims themselves attempt to file.

The organization is working with its Digital team to assist with investigation and remediation efforts and has expressed its commitment to deploying additional safeguards to prevent similar incidents in the future.

Even in the absence of confirmed misuse, exposure of Social Security numbers and tax data can create long-term risks. Affected individuals may face tax-related identity theft, delayed refunds, or unauthorized financial activity.

At Class Action U, we believe employees should not bear the burden when organizations fail to properly train staff or implement safeguards against phishing schemes. If your information was exposed, you may have legal options.

When Did This Breach Occur?

The spear-phishing incident occurred on February 3, 2026.

PLOS discovered and reported the incident on the same day and immediately initiated an investigation.

What Information Was Breached?

The personal information involved includes:

  • 2025 Form W-2

  • Name

  • Residential address

  • Social Security number

  • Salary information

  • Tax withholding information

This combination of tax and identity data significantly increases the risk of fraudulent tax filings and identity theft.

What You Can Do

If you were notified by PLOS that your W-2 information was disclosed, consider taking the following steps immediately:

  • File your tax return as early as possible to reduce the risk of fraudulent filing.

  • Monitor your IRS account for unusual activity.

  • Consider requesting an Identity Protection PIN (IP PIN) from the IRS.

  • Review your credit reports and monitor financial accounts for suspicious activity.

  • Report suspected tax-related identity theft to the IRS and file a report at IdentityTheft.gov.

Remaining vigilant is critical, especially during tax season. Tax-related identity theft can take significant time and effort to resolve.

You may also want to explore your legal rights if your sensitive tax information was exposed due to this incident.

File a Data Breach Lawsuit Against Public Library of Science

If your W-2 and Social Security number were disclosed in the PLOS data breach, you may be eligible to pursue compensation. Exposure of tax and Social Security information creates serious risks, including fraudulent tax filings and long-term identity theft.

Class action lawsuits allow affected individuals to join together to hold organizations accountable for failing to prevent foreseeable phishing attacks.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
Other Data Breaches
Date of Breach: June 16, 2025
Date of Breach: February 3, 2026
Date of Breach: December 14, 2025

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.