Payroll Diversion and Direct Deposit Change Scams in Construction

Fraudsters impersonate employees to redirect paychecks. Learn how the scam works and how payroll teams can verify changes without slowing down.

4 min readBy Ironfield Cyber Team

Payment diversion is usually discussed in terms of vendors and subcontractors, but employees are targets too. In a payroll diversion scam, a criminal pretends to be an employee, or takes over the employee's email account, and asks payroll to change the direct deposit details. The next paycheck goes to the fraudster's account, and the employee finds out when they discover they were not paid.

Construction is especially exposed because of large field workforces, seasonal hires, many pay periods and employees who rarely sit at a computer. A foreman might genuinely send a text from a truck asking to update a bank account, which makes the legitimate request look much like the fraudulent one.

How the scam typically works

  1. The attacker gathers information about an employee, from social media, a data breach or a phishing email that captures an email password.
  2. They email payroll, or HR, from a lookalike address or from the real mailbox, asking to update direct deposit information before the next payday.
  3. The message is brief and plausible. It may mention a bank change or a new account and ask for confirmation.
  4. If payroll complies, pay is redirected to an account controlled by the attacker, often a prepaid card or an account that quickly moves the money.
  5. The real employee notices only when the deposit does not arrive.

Sometimes the attacker also targets payroll portals directly, using stolen credentials to change bank details without ever contacting a person.

Why it succeeds

  • Payroll teams want to be helpful and process requests quickly.
  • Requests look routine, and employees really do change banks.
  • Verification is inconsistent, especially when the employee is in the field.
  • Nobody reviews changes unless a complaint arrives.
  • Portals lack multi-factor authentication or alerts.

Build a verification routine

The best defense is a simple, consistent rule: no direct deposit change is made on the strength of an email or text alone.

Recommended steps

  1. Use a standard form or portal. Changes come through one channel, such as an employee self-service portal protected by MFA or a signed form delivered in person or via a secure method.
  2. Verify by a second channel. Call the employee using the number already on file, or confirm face to face at the yard, shop or jobsite. Do not use contact details provided in the request.
  3. Check for context. Ask a question only the employee would know that is not easily found online, or have the supervisor confirm the request.
  4. Delay the first payment slightly after a change. A short hold or a prenote test deposit, if your bank supports it, gives time to catch problems.
  5. Notify the employee of every change. Send a confirmation to their existing contact information, so a real employee can object quickly.
  6. Require a second person to approve. Especially for the first change after hire or for accounts that change repeatedly.

Be clear that these steps apply to everyone, including executives. Exceptions undermine the process.

Flag unusual patterns

Ask your payroll system or provider to report on direct deposit changes each pay period. Look for:

  • Multiple employees changing to the same account number
  • Changes made shortly before payday
  • Changes to accounts at banks that are new to your records
  • Changes preceded by password resets or logins from unusual locations
  • Several changes requested from a single email address

A short weekly review catches anomalies quickly.

Secure the portals

  • Require multi-factor authentication for employee and administrator access to payroll systems.
  • Enable alerts when banking details are changed.
  • Use strong, unique passwords, and encourage a password manager.
  • Review administrator accounts and remove those no longer needed.
  • Prevent employees from sharing logins with spouses, coworkers or supervisors.

Educate employees

Include a short note in new-hire materials and a periodic reminder.

  • Payroll will never change your bank details based on a text or email alone.
  • Never share your payroll login or verification codes.
  • Report any message that claims to be from payroll or HR asking for your information.
  • If a paycheck does not arrive, tell payroll the same day.

Respond fast if it happens

Speed improves the chance of recovering funds.

  1. Contact your bank immediately to request a recall or freeze.
  2. Notify the payroll provider.
  3. Reset the affected employee's passwords and review the mailbox for forwarding rules and unauthorized access.
  4. Preserve emails and logs.
  5. Consider the employee's personal exposure, and offer guidance on protecting accounts.
  6. Report to law enforcement and, as appropriate, the FBI's Internet Crime Complaint Center.
  7. Make sure the employee is paid promptly, and document the incident.

A final word

These scams succeed on routine and speed. A short, written process that every payroll clerk follows turns routine into a control. Ironfield Cyber helps contractors design verification procedures and secure payroll platforms, and we are glad to review yours with the payroll team.