Double-Check Systems for Payroll Redirect and Direct Deposit Fraud

Fraudsters impersonate employees to redirect paychecks to new bank accounts. Put simple verification checks in place before payroll changes go through.

3 min readBy Ironfield Cyber Team

Wire fraud against vendors gets most of the attention, but payroll is a quieter target. In a common scheme, a criminal impersonates an employee, often through a spoofed or compromised email account, and asks HR or payroll to change the direct deposit information. The next paycheck lands in an account the criminal controls, and the real employee finds out when pay does not arrive.

For contractors with large field workforces, seasonal crews, and many employees who rarely sit at a desk, the risk is real. Fortunately, a few simple checks stop most attempts.

How payroll redirection works

The typical sequence looks like this.

  1. An attacker gets access to an employee's email or creates a convincing look-alike address.
  2. They email payroll or HR, claiming to have changed banks, and ask for new deposit details.
  3. The change is made on the strength of the email alone.
  4. The attacker withdraws or moves the funds before anyone notices.

Variations include attackers logging directly into self-service payroll portals using stolen credentials, and phone calls to help desks that reset passwords or contact details.

Build verification into the change process

Never accept banking changes by email alone

Require employees to submit changes through an authenticated channel, such as the payroll system's self-service portal protected by multifactor authentication, or in person. If a request comes by email or text, treat it as unverified until confirmed another way.

Confirm by a trusted method

Call the employee at a phone number already on file, or speak to them face to face, before completing the change. Do not use contact details from the request itself. For field employees, ask a supervisor to confirm in person or by a known phone number.

Add a waiting period or a confirmation message

Some payroll systems let you notify the employee at their existing contact details whenever banking information changes, and delay the first payment. Even a short delay gives the real employee a chance to say, "I did not do that."

Limit who can make changes

Restrict the ability to change direct deposit information to a few trained people, and log every change. Make sure a second person reviews changes to banking details periodically.

Protect the payroll system itself

  • Require multifactor authentication for all payroll and HR portals, including employee self-service.
  • Disable accounts promptly when people leave, and review administrator access regularly.
  • Use unique, strong passwords and discourage reuse of work passwords elsewhere.
  • Review reports of banking changes before each payroll run. Many systems can generate a list of accounts changed since the last cycle.
  • Watch for multiple employees whose accounts changed to the same bank account number, which suggests fraud.

Train the right people

Payroll and HR staff are the front line. Show them real examples of impersonation emails and practice the verification script. Make clear that following the process is never rude and never gets anyone in trouble, even if the request appears to come from an executive.

Employees should also be told that the company will never ask them to send banking details by email or text, and that any unexpected request should be reported.

If a payroll change goes wrong

Act fast.

  1. Contact your bank and payroll provider immediately to attempt to stop or recall the payment.
  2. Secure the affected employee's accounts and reset credentials, including email.
  3. Review whether other employees were targeted or changed.
  4. Notify the employee and provide support, since they may be financially affected.
  5. Consider reporting to law enforcement and the FBI's Internet Crime Complaint Center, and notify your insurer as your policy requires.
  6. Review how the request bypassed verification and fix the gap.

Time matters, and early contact with the bank offers the best chance of recovery, though success is never guaranteed.

Quick checklist

  • Banking changes only through verified channels
  • Callback to a known number for every request received by email
  • Notifications to the employee on any change
  • Multifactor authentication on all payroll access
  • Pre-payroll review of changed accounts
  • Trained staff and a written procedure

Where Ironfield Cyber fits

Ironfield Cyber helps HR and payroll teams secure employee portals, tighten email protections, and write verification procedures that field-heavy companies can actually follow. If you would like a review of your payroll change process, we are happy to help.