Payroll Diversion Fraud: When a Fake Email Reroutes an Employee’s Paycheck

A Paycheck That Never Arrives

Payroll diversion fraud follows a simple, effective script: an attacker sends an email that appears to come from an employee, requesting a direct deposit change, and HR or payroll makes the change without verifying it out-of-band. The next payday, the real employee’s paycheck lands in an account the attacker controls, and by the time anyone notices, the money is long gone. It’s a fast-growing subtype of business email compromise (BEC), and it specifically targets the people least likely to be included in a general phishing-awareness training: HR staff and bookkeepers handling routine administrative requests.

This guide covers exactly how payroll diversion attacks work, why they succeed even at businesses with reasonable security awareness, and the direct-deposit change controls that stop them.

How the Attack Actually Works

Payroll diversion doesn’t require hacking your payroll system. It only requires convincing one person to make one change. The typical sequence:

  1. Reconnaissance. The attacker identifies a target business, often through LinkedIn, a company website’s staff directory, or a prior data breach that exposed employee names and roles — the same kind of exposed data covered in our guide on dark web monitoring. Real names make the impersonation convincing.
  2. The spoofed or lookalike email. An email arrives appearing to come from a real employee — either a spoofed sender address, a lookalike domain (a single character swapped, or a free email provider mimicking the employee’s name), or in some cases a compromised personal email account. The message is short and routine: “Hi, I switched banks — can you update my direct deposit info for this pay period?”
  3. Urgency and plausibility. The message often references an upcoming pay date to create time pressure, and sometimes includes a forged or convincing-looking bank letter or voided check to add legitimacy.
  4. The change is processed. If HR or payroll updates the direct deposit information based solely on the email — without a callback to a known phone number — the next payroll run sends the employee’s wages directly to the attacker’s account.
  5. The employee finds out on payday. Often the first sign of the attack is an employee reporting their paycheck never arrived — by which point the funds have typically already been withdrawn.

Why It Works Even at Security-Aware Businesses

Most phishing and BEC training focuses on invoice fraud and wire transfer scams aimed at finance and executives. Payroll diversion targets a different, often-overlooked group: HR administrators and bookkeepers processing what looks like a completely mundane, low-risk request. A direct deposit change doesn’t trigger the same scrutiny an executive wire transfer would — it feels routine, even boring, which is exactly why attackers favor it. There’s also no large single loss to notice immediately; the diverted amount is one paycheck at a time, and if payroll runs biweekly, a business may process two or three diverted paychecks before the real employee reports the problem.

This attack shares a lot of DNA with the general business email compromise patterns covered in our what is business email compromise guide, but the specific target — payroll and HR staff, not finance and executives — means a general BEC training pass often misses it entirely.

The Direct-Deposit Change Controls That Stop It

The fix here isn’t complicated, but it has to be enforced without exception, including for the CEO’s own paycheck:

  • Require verbal or in-person confirmation for every direct deposit change using a phone number already on file for the employee — never a number provided in the request email itself. This is the same known-number callback principle covered in our payment verification callback procedure guide, applied specifically to payroll.
  • Add a mandatory waiting period between when a direct deposit change is requested and when it takes effect — typically one full pay cycle — giving time for the change to be verified and for any fraud to surface before money moves.
  • Notify the employee through a separate channel (a text to their known personal number, or an in-person confirmation) whenever their banking information changes, so a legitimate employee immediately catches a fraudulent change made in their name.
  • Restrict who can process direct deposit changes and require a second person to review and approve any change before it’s submitted to payroll processing — the same least-privilege thinking covered in our guide on least privilege and just-in-time access.
  • Train HR and payroll staff specifically on this pattern as part of regular security awareness training — general phishing training aimed at finance and executives routinely misses this administrative-request angle entirely.
  • Watch for lookalike domains and newly registered sender domains in any request touching banking or payroll information — email authentication controls like SPF, DKIM, and DMARC reduce (but don’t eliminate) the chance of a convincingly spoofed internal sender.

Who Actually Eats the Loss

This is the question every business owner asks after a payroll diversion incident, and the honest answer is: it depends, and it’s often the business. Many payroll processors and banks treat a direct deposit change as an authorized instruction once submitted through normal channels — meaning the business, not the bank, absorbed the loss unless fraud can be clearly demonstrated and reported quickly. Some cyber insurance policies cover payroll diversion under a social engineering fraud endorsement, but many standard policies exclude it or cap coverage well below the actual loss — this is exactly the kind of gap worth checking explicitly when reviewing a policy, not assuming is automatically covered under generic “cyber crime” language.

The employee whose paycheck was diverted is also affected directly — they didn’t get paid on time through no fault of their own, and most businesses make the employee whole immediately (from operating funds, recovered separately if possible) rather than leaving them to wait on an investigation, both for legal wage-payment obligations and for the obvious trust and morale impact of telling an employee they simply won’t be paid this cycle.

What to Do If a Payroll Diversion Attack Succeeds

  1. Contact your bank immediately to attempt a recall of the funds — this works far more often within the first 24 hours than after.
  2. Notify your payroll processor and freeze any further changes to the affected account pending investigation.
  3. File a report with the FBI’s Internet Crime Complaint Center (IC3) and your local police — see our guide on how to report a cyberattack for the full process.
  4. Make the affected employee whole on the missed pay as quickly as your cash flow allows, separate from the recovery process.
  5. Reset the direct deposit change process immediately — require verified reconfirmation of banking details for every employee going forward, not just the one affected.
  6. Review whether other employees received similar impersonation attempts around the same period; payroll diversion attacks are frequently run against multiple employees at the same company in a short window.

Bottom Line

Payroll diversion fraud succeeds by hiding inside a routine administrative task, aimed at the people least likely to be included in executive-focused fraud training. The fix is a mandatory, no-exceptions callback verification for any direct deposit change, using a phone number already on file — never one supplied in the request itself — plus a short waiting period and a separate-channel notification to the employee whenever their banking details change. None of this requires new software or a security budget increase; it requires making one administrative process slightly slower and non-negotiable.

Train your team the easy way

Our Security Awareness Training Kit includes a training guide, phishing one-pager, quiz, sign-off form, and a completion tracker.

Get the Training Kit ($29) →

From Veteran Forge · editable template · instant download

Similar Posts