Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Payroll Diversion Fraud: When HR Email Gets Hijacked

July 14, 2026

Payroll diversion fraud is a targeted cyberattack where a criminal tricks your HR or accounting department into rerouting a paycheck to a fraudulent bank account. The attacker sends a brief, realistic email. It pretends to be an employee who needs to update their direct deposit information. Because the request looks routine, the change is often processed without a second thought.

This is a highly effective variant of business email compromise payroll scams. Unlike massive wire fraud attempts that target executives, this attack asks for relatively small amounts. The FBI’s Internet Crime Complaint Center put the average loss at $7,904 per complaint. These scams fly under the radar of executive approval. They exploit the natural helpfulness of your HR staff.

The scam relies entirely on bypassing identity verification. By the time the real employee notices a missing deposit and complains to management, the money is gone. Protecting your business requires three things: strict financial controls, employee training, and IT security that takes email out of the payment change process.

What Is Payroll Diversion Fraud and How it Works

The employee paycheck redirect scam usually begins with reconnaissance. Attackers scour LinkedIn and corporate websites to identify your HR managers, payroll administrators, and general employees. Once they have names and roles, they pick one of two attack methods.

AspectSpoofed-Email HR ImpersonationHRIS Portal Credential Theft
How it startsA fake email address that looks nearly identical to a real employee’s personal or work address contacts your payroll staff directlyA phishing email sends the employee a fake login link for your company’s human resources information system
What the attacker doesAsks payroll to update banking details, often including a voided check or a standard direct deposit form filled out with the attacker’s routing and account numbersCaptures the employee’s username and password, then logs into the real HR portal and changes the direct deposit routing numbers directly
What it leaves for it to findA brief, polite, direct email sitting in the payroll inboxNo obvious email trail, since the change happens inside the portal itself

Payroll fraud HR impersonation through spoofed emails tends to be the easier method. It does not require stealing a working password first. HRIS portal credential theft is the more dangerous one. It bypasses your HR staff entirely. Administrators have nothing to spot in the email trail.

Why the Scam Succeeds

HR teams process administrative changes every week. When a direct deposit update comes in from a recognized name, the natural instinct is to process it quickly. Everyone wants the employee to get paid on time. This routine nature makes HR payroll fraud phishing incredibly successful.

Criminals also know that payroll diversion red flags are subtle. Watch for:

  • A false sense of urgency, such as a claim that an old bank account just closed and the new one needs to be active immediately for the upcoming pay cycle.
  • A slightly altered email domain that’s easy to miss when payroll administrators are busy.
  • A generic Gmail address used in place of a corporate account.

The theft typically goes unnoticed until the next payday. The real employee checks their bank account, sees no deposit, and contacts payroll. Only then does the company realize the routing numbers were changed by an imposter. At that point, the criminal has already received the funds and moved them. Recovery becomes extremely difficult.

Payroll Diversion Prevention Strategies

You cannot rely on email to verify financial changes. Effective payroll diversion prevention requires strict, nonnegotiable processes that remove trust from the equation. Every single payroll account change verification must happen out of band:

  • Call to verify. If an email requests a bank change, pick up the phone and call the employee at a known, trusted number currently on file. Never reply to the requesting email to confirm the change.
  • Remove email from the process. Force all direct deposit changes through a secure self service portal instead.
  • Enforce multi-factor authentication. MFA on that portal stops an attacker who has stolen a password through phishing from logging in and altering the banking details.
  • Train your team. Teach your HR and accounting staff to recognize the specific language used in these attacks.
ControlWhat it stopsImplementation effort
Call to verifySpoofed email impersonationLow
Self-service portalSpoofed email + credential theftMedium
Multi-factor authenticationCredential theftLow
Staff trainingSocial engineering blind spotsMedium

Speaking to the employee directly is the only way to verify the request is legitimate. You can use the free self-assessment to evaluate your current financial controls. See where your vulnerabilities lie. Implementing these it controls and strict verification rules is the only reliable way to protect your payroll cycle.

What to Do If it Happens

If your business falls victim to direct deposit fraud employees, you must act immediately. Speed is critical.

Acting fast is the only real chance you have to reverse a fraudulent transfer once the funds are sent. In 2024, the FBI IC3 received 21,442 business email compromise complaints, with $2.77 billion in adjusted losses.

  1. Contact your originating bank immediately to request a wire recall or ACH reversal, and explain that the transfer was fraudulent.
  2. File a detailed report at IC3.gov. The FBI IC3 Recovery Asset Team assists in freezing funds for victims. The IC3 payroll diversion warning stresses that rapid reporting significantly increases your chances of recovering the stolen funds.

Next, address the internal side of the incident while the bank and law enforcement work on the financial recovery.

  1. Make your employee whole. Because the business authorized the fraudulent transfer, it typically ends up covering the loss, while the employee still gets paid for the work they performed.
  2. Have your IT security team perform a comprehensive mailbox audit. Determine exactly how the attacker communicated with your staff. Did they simply spoof an outside email address? Or did they breach your internal network and compromise a user account?

See Where You Stand

Free 2-minute BEC Exposure Check: 9 quick questions on how your business moves money, see your exposure level and the gaps to fix. No sign-up to see your result. free business email compromise risk check

Frequently Asked Questions

What are the red flags of payroll fraud?

Red flags include urgent requests to change direct deposit details right before a payroll cutoff. You might also see emails originating from personal addresses rather than a corporate account. Unfamiliar bank routing numbers or a sudden change in an employee’s writing style are also strong warning signs.

Who eats the loss in payroll diversion fraud?

The employer typically bears the financial loss in a payroll diversion scam. Because the company’s human resources or payroll department authorized the fraudulent transfer, the business is responsible for replacing the missing wages. The employee must still be paid for the time they worked.

What is diversion fraud?

Diversion fraud is a social engineering attack where a criminal manipulates a business into sending money to a fraudulent account. The attacker impersonates a trusted entity like an employee, vendor, or executive. They intercept a legitimate payment process and divert the funds to a bank account they control.

What are some examples of payroll fraud?

Common examples include ghost employees, falsified timesheets, and unauthorized bonus payouts. In the cybersecurity context, the most common example is a direct deposit redirect scam. An attacker compromises an employee email account and tricks HR into routing the next paycheck to a criminal’s bank account.

What evidence is needed to prove fraud?

Proving fraud requires documentation of the fraudulent communication and the resulting financial transaction. You need the original phishing emails, network logs showing unauthorized portal access, and the bank transfer records. This evidence is critical when filing a report with the FBI IC3 and your financial institution.

Secure Your Payroll Systems

We build the payment verification processes, enforce multi-factor authentication, and monitor email rules to stop payroll diversion attacks before they reach your staff. LeadingIT has helped Illinois businesses stay secure since 2010.

If you need help securing your human resources systems, start here:


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.