Credential theft is the acquisition of someone's username and password by an attacker. It is the most common precursor to employer fraud, because almost every scheme that reaches HR or payroll begins with someone else logging in as a legitimate user.
The uncomfortable part for employers is that the theft usually happens somewhere they have no visibility — a consumer website the employee used, a personal device, a phishing page — and only becomes their problem when the stolen password also works on a company system.
Password reuse. The largest single source. An employee uses the same password on a shopping site and on their work email. The shopping site is breached, the credentials appear on a list, and automated tools test that list against employer logins. No sophistication is required.
Phishing pages. A convincing replica of a login screen — usually email, the HRIS, or the payroll portal. The employee enters their password and it goes straight to the attacker, often while the page forwards them to the real site so nothing seems wrong.
Infostealer malware. Software on a personal or work device that harvests saved browser passwords in bulk. Frequently arrives through downloads unrelated to work, which is why personal devices with company access matter.
Vishing. A phone call impersonating IT support, walking the employee through providing credentials or approving an authentication prompt.
Session token theft. More advanced: stealing the authenticated session rather than the password, which can bypass multi-factor authentication entirely.
The employee whose credentials are stolen is rarely the target. Their mailbox is the platform.
From a compromised mailbox, an attacker can read the payroll calendar, learn vendor relationships, identify who approves payments, and send requests to colleagues from a genuinely legitimate address. They can run password resets on every other system that uses that address for recovery. And they can create inbox rules that hide the replies, so the real employee never sees the conversation happening in their name.
This is why email is the highest-priority system to protect, ahead of even payroll: it is the key to everything else.
Multi-factor authentication. It breaks the entire reuse chain — a leaked password alone stops being sufficient to log in.
The priority order for an employer is email first, then payroll, HRIS, the employee self-service portal, and any banking or benefits platform. The self-service portal is the one most often left on a password alone, which is precisely where an attacker with stolen credentials changes a direct deposit account.
Not all factors are equal. Authenticator apps beat SMS, which is vulnerable to SIM-swap. Push approvals should use number matching, or attackers simply spam prompts until someone taps approve. Hardware keys resist phishing outright and are worth deploying for payroll administrators, finance, and executives even if not workforce-wide.
Speed matters more than thoroughness in the first hour. Reset the password and revoke active sessions — a reset alone does not always terminate an existing session, which is a frequent oversight.
Then check for persistence: inbox rules, forwarding addresses, delegated mailbox access, and registered MFA devices the attacker may have added. Attackers routinely add their own second factor so a password reset does not lock them out.
Assess what the mailbox contained and whether any employee data was accessible, since that may trigger notification obligations. Check whether requests were sent from the account to colleagues, vendors, or payroll. And review whether other employees received the same phishing message, because these campaigns are rarely singular.
The employee who realizes they entered their password on a fake page needs to say so within minutes, not agonize about it for a week. An organization where that report is met with thanks contains the incident; one where it is met with blame finds out from the bank.
Employer's Guardian helps employers set authentication standards and train staff on the specific credential attacks aimed at HR and payroll through workforce training.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.