401(k) account fraud is the unauthorized withdrawal, loan, or transfer of funds from an employee's retirement account. It is a growing category of workforce fraud with a characteristic that makes it unusually damaging: the theft frequently goes unnoticed for months, because most employees check their retirement balance far less often than their bank account.

For employers, the awkward part is that the money sits with a recordkeeper rather than in company accounts — but the employee's relationship is with the employer, and so is the fallout.

How the accounts get taken over

The typical route is not a breach of the plan provider. It is credential-based takeover of an individual participant.

Attackers obtain an employee's email credentials, often from an unrelated consumer breach where the person reused a password. From the mailbox they identify the retirement provider, run a password reset, intercept the confirmation, and gain access. They then change the contact details on file, request a distribution or loan, and route it to an account they control.

A second route targets accounts that were never registered online. Many employees, particularly those auto-enrolled, have never set up web access. An attacker with enough personal data can complete first-time registration in the employee's name — and because the real employee has no account, there is nothing to alert them.

That second pattern is worth communicating to a workforce directly: registering the account is itself a protective step, even for someone with no intention of logging in again.

Why detection is slow

Retirement statements are typically quarterly. Confirmation emails go to whatever address is on file — which the attacker has already changed. Employees do not receive the real-time alerting they have come to expect from a bank.

Discovery therefore often happens at the next statement, or when the employee logs in for an unrelated reason. By then the funds are gone and the question of who bears the loss has become contested.

Where employer responsibility sits

This is the part employers most often misjudge. Sponsoring a retirement plan carries fiduciary responsibilities, and those extend to prudent selection and monitoring of the service providers holding participant accounts.

Regulators have issued cybersecurity guidance for plan sponsors, service providers, and participants. The practical effect is that an employer cannot treat account security as entirely the recordkeeper's problem. A sponsor that never asked its provider about cybersecurity practices, never reviewed them, and cannot document having done so is in a weaker position when a participant loses money.

Whether a provider makes a defrauded participant whole varies by provider and circumstance, and often turns on whether the participant followed the provider's own security requirements. That variability is itself a reason to understand the policy before an incident rather than during one.

What sponsors should be doing

  • Ask the recordkeeper directly what account security controls exist, whether MFA is available and whether it is on by default, how distribution requests are verified, and what their policy is on restoring participant losses
  • Document that inquiry and revisit it periodically, since demonstrating prudent monitoring is the point
  • Push for MFA enabled by default rather than optional, because optional security is rarely adopted
  • Confirm change-of-address and change-of-banking procedures include verification through a channel the requester did not supply
  • Ask about hold periods after a contact detail change before a distribution can process — this single control defeats most takeovers
  • Review the provider's incident notification commitment to the sponsor

What employees should be told

A short, direct communication does more here than most technical measures, because participant behavior is the main variable.

Employees should be told to register their online account even if they do not plan to use it, enable multi-factor authentication, never reuse their work or retirement password elsewhere, check the account at least quarterly, and report immediately if they receive an unexpected notification about a change they did not make.

That last point turns participants into the detection mechanism for the one attack the provider's controls may not catch.

The wider pattern

401(k) takeover is one expression of a broader problem: employee-facing financial platforms protected by a password alone, where the employer assumes the vendor has it handled and the vendor assumes the participant does.

The same reasoning applies to health savings accounts, equity platforms, and any benefits system holding a balance. Employers reviewing authentication and change-verification practices across all of them tend to find the same gaps in each.

Employer's Guardian helps employers evaluate benefits and retirement providers, document that diligence, and communicate protective steps to their workforce through outsourced HR services.

This article provides general educational information, not legal, tax, or investment advice. Retirement plan fiduciary obligations are specific and consequential. Consult qualified counsel or your plan advisor regarding your responsibilities.

Let's Talk! Schedule a Conversation

For additional information, pricing, and/or free consultation, contact us. We'd be happy to discuss your situation.

Contact Us Today!

Want a professional to walk you through your HR needs shopping list?

At Employer’s Guardian, our experts are here to help. We are happy to work with you to understand your HR needs. Get in touch—give us a call or fill out our online contact form and we’ll promptly get back to you!

Contact Us Today!