Payroll and Direct Deposit Scams: BEC Beyond Wire Fraud

Business email compromise also targets payroll. Learn how direct deposit change scams work and the verification steps that protect your employees' paychecks.

3 min readBy Ironfield Cyber Team

When people hear business email compromise, they think of large wire transfers and vendor invoices. Attackers also go after payroll, using a simpler trick: convince HR or payroll to redirect an employee's paycheck to a new bank account. The amounts are smaller per incident, but the scam is easy to repeat, easy to miss and harmful to the employee who does not get paid.

Contractors with large, changing workforces, including seasonal crews and field staff who rarely visit the office, are especially exposed. Payroll teams handle many routine change requests, and verification often depends on habit rather than policy.

How the scam works

  1. The attacker obtains an employee's email credentials through phishing, or simply spoofs the employee's address.
  2. They send a message to payroll or HR asking to update direct deposit information, often with a plausible reason such as a new bank.
  3. The request may include a voided check image or account details.
  4. Payroll updates the record and the next paycheck goes to the attacker.
  5. The employee notices only when pay does not arrive, sometimes days later.

Variations include fake requests through HR portals after an account takeover, and calls from someone posing as the employee.

Why it works in construction and energy

  • Many employees work remotely or in the field and are not physically available to confirm requests
  • Turnover and seasonal hiring produce a steady stream of legitimate banking updates
  • Payroll staff are busy and processing deadlines are tight
  • Employees use personal email and phones, which are less protected
  • Employee information, such as names and job titles, is easy to find

Controls that work

Require out-of-band verification

Never accept a change based on email alone. Confirm through a separate channel: a call to a phone number already on file, a face-to-face check with a supervisor or a request submitted through a secured portal that requires multi-factor authentication.

Use a secure self-service portal

A portal where employees update their own information, protected by MFA, is safer than email requests. If you use one, make sure account recovery cannot be abused by someone with only an email address.

Add a waiting period and notification

A short delay before a banking change takes effect, plus an automatic notice to the employee's email and phone on file, gives the real person a chance to object. Where possible, notify through more than one channel.

Flag unusual changes

Treat certain patterns as red flags:

  • Changes requested shortly before payday
  • New accounts at online-only banks or prepaid card providers, which are sometimes used by fraudsters, though they have legitimate uses too
  • Requests from personal email addresses that differ from those on file
  • Multiple employees requesting changes to the same account
  • Pressure to hurry

Limit who can change payroll data

Only a small number of trained staff should be able to edit banking details. Use separate duties so that the person who processes payroll is not the only one reviewing changes. Send a weekly report of all banking changes to a manager.

Protect the accounts that matter

Require MFA on email, payroll platforms and HR systems. Compromised mailboxes are the root cause in many of these scams, and strong authentication removes much of the opportunity.

Train HR and payroll staff

  • Walk through the scam with real-looking examples
  • Give staff explicit authority to say no or delay requests until verified
  • Make sure they know who to alert immediately if they suspect a scam
  • Explain that managers will support them, even if a legitimate request is delayed

If a payment was diverted

Speed matters.

  1. Contact your bank immediately to attempt to stop or recall the transfer.
  2. Reset credentials and review access for the affected employee and any compromised accounts.
  3. Preserve emails and logs for investigation.
  4. Notify your insurer as required by your policy.
  5. Consider reporting to law enforcement, including the FBI's Internet Crime Complaint Center.
  6. Communicate with the employee and arrange to make them whole according to your policies and applicable law.
  7. Review what allowed the change and fix the gap.

A hypothetical example

Consider a hypothetical foreman whose email account is compromised through a fake sign-in page. The attacker emails payroll asking to change his direct deposit, attaching a voided check. Payroll updates the account the same afternoon. If the company had required a call to the foreman's known mobile number before any bank change, the request would have failed.

Support

Ironfield Cyber helps contractors and energy companies harden payroll processes, secure email and HR platforms, and train staff to spot fraud. If you want a second opinion on your verification steps, we can review them with your HR and finance teams.