Direct-Deposit Fraud: What Employers Need to Know
August 18, 2026
Direct-deposit fraud is the redirection of an employee's wages to an account controlled by an attacker. It is the most common payroll fraud aimed at employers, it requires no technical skill, and it succeeds through a single unverified request rather than through any system compromise.
The distinguishing feature is who absorbs the harm. Most fraud against a business takes company money. This takes an employee's paycheck, which means the employer faces both a financial loss and a workforce that has been directly harmed by an internal process failure.
How the request reaches HR
The typical approach requires only public information. An attacker identifies an employee and their employer through a professional networking profile, then contacts HR or payroll posing as that person — usually from a lookalike email address, occasionally by phone, sometimes through a compromised employee account.
The message is unremarkable. It says the employee changed banks and needs their direct deposit updated. It frequently includes a completed change form, often the employer's own form downloaded from a public page, which makes it look more legitimate rather than less.
The version that defeats most checks is the one sent from the employee's genuine email account after that account has been compromised. Every sender-based verification passes. Only confirmation through a separate channel catches it.
Why the timing is deliberate
Requests cluster immediately before payroll processing closes. This is not incidental. The attacker needs the change applied before anyone scrutinizes it and needs funds to settle before the employee notices a missing payment.
The compressed timeline also suppresses verification. A request arriving with hours to spare creates pressure to process quickly, and an HR professional trying to ensure a colleague gets paid on time is inclined to accommodate it. The urgency is the attack.
The discovery gap
Detection usually happens when the employee reports not being paid — which is generally the day after payday, sometimes later if they do not check immediately. By then the funds have settled and been withdrawn. Fraudulent receiving accounts are typically drained within hours and are often prepaid cards or newly opened accounts that close shortly afterward.
Recovery in that window is unlikely. Return rights for business ACH entries are narrow and generally do not cover payments the employer authorized based on fraudulent instructions — the employer authorized it, and the instruction was false. That places the loss with the employer in most circumstances.
The wage obligation does not go away
This is the point employers most often misjudge. Paying a fraudulent account generally does not satisfy the obligation to pay the employee. The employee worked and has not been paid, and in most circumstances remains entitled to those wages. The employer absorbs the diverted amount and still owes the paycheck.
In California, delay compounds the exposure. Wage payment timing requirements are strict, and an employee left unpaid while an employer investigates may have claims beyond the wages themselves. The practical guidance is to make the employee whole promptly and treat recovery as a separate matter, rather than withholding pay pending resolution.
Prevention, which is effectively the whole strategy
Because recovery is improbable, prevention carries the entire load. One control does most of the work:
Out-of-band verification. Every banking change is confirmed by contacting the employee through details already held in the HR system — never a number or address supplied in the request. Two minutes, and it defeats both the lookalike-address version and the compromised-account version.
Reinforcing measures:
- A waiting period holding banking changes for a full cycle, which removes the urgency the scheme depends on
- Notification to the address of record whenever banking details change, giving the real employee a chance to object before payday
- Two-person approval so one rushed employee cannot complete the change alone
- Restricted edit rights limiting how many people can be targeted
- Pre-run review of all banking changes since the last cycle, as a distinct step before payroll finalizes
- Multi-factor authentication on self-service portals, which are otherwise a direct route for anyone with stolen credentials
Self-service does not remove the risk
Employers using employee self-service portals sometimes assume the exposure is gone because employees make their own changes. It is not — compromised credentials let an attacker make the change directly, with no human to notice anything unusual. Portals should require step-up authentication for banking changes and notify the employee's address of record automatically.
When it happens
Contact the bank immediately, as the only realistic recovery window is measured in hours. Make the employee whole promptly. Determine whether the employee's email account was compromised, since if it was, the exposure extends beyond one paycheck. Review whether other employees received similar requests, as these campaigns rarely target a single person. And document the incident, which matters for both insurance and any subsequent claim.
Employer's Guardian helps employers establish verification and review practices that stop these requests before funds move, through payroll services.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.

