Payroll diversion is a fraud scheme in which an attacker reroutes an employee's wages to an account they control. It rarely involves breaking into a payroll system. In most cases the attacker simply asks someone in HR or payroll to update a direct deposit record, and the request looks close enough to routine that it gets processed.
For employers, this is one of the few fraud types where the loss lands directly on the workforce. An employee works a full pay period and receives nothing, while the money settles into a prepaid card or a short-lived checking account and is withdrawn within hours. The employer then has to decide whether to make the employee whole, which in practice they almost always do.
Attackers go where the authority sits. The ability to change where an employee's money goes is held by payroll administrators and HR staff, not by the security team. That makes payroll one of the highest-value targets in an organization while often being one of the least hardened, because the controls around it are procedural rather than technical.
The scheme also exploits a real tension in HR work. HR teams are measured on being responsive and helpful to employees. A request that says "I switched banks and need my deposit updated before Friday" is exactly the kind of request a good HR professional wants to resolve quickly. The attacker is counting on that instinct.
A common sequence looks like this. The attacker identifies an employee through a public source such as a professional networking profile or a company directory. They register a lookalike email address, often changing a single character or using a free email provider with the employee's real name. They send a message to HR or payroll asking to update direct deposit details, sometimes attaching a filled-out form pulled from the employer's own public website.
If the request is processed without an independent verification step, the change takes effect on the next payroll run. The fraud is usually discovered only when the employee reports a missing paycheck, which means the loss is already several days old and the funds are gone.
A more advanced version begins with a compromised employee email account. In that case the request arrives from the genuine address, which defeats any check based on matching the sender. This is why verification has to happen through a separate channel rather than by replying to the message.
The single most effective control is out-of-band verification. Any change to direct deposit information should be confirmed by contacting the employee through a channel already on file, using a phone number retrieved from the HR system rather than one provided in the request. This one step defeats both the lookalike-address version and the compromised-account version of the scheme.
Beyond that, a small number of procedural controls carry most of the weight:
Wage payment obligations do not disappear because a third party intercepted the funds. In most circumstances an employer that pays a fraudulent account has not satisfied its obligation to pay the employee, which means the employer absorbs the loss and still owes the wages. In California, late or unpaid wages can also raise exposure under state wage payment rules, which is why payroll diversion is worth treating as a compliance issue rather than purely a fraud issue.
Recovery is possible but time-sensitive. If the fraud is caught within a day or two, the receiving bank can sometimes freeze the funds. After that the money is usually unrecoverable, which is why detection speed matters more than any post-incident process.
Payroll diversion is one expression of a wider problem: payroll processes that were designed for convenience rather than for verification. Employers that tighten change verification generally find the same controls also address related schemes such as payroll impersonation, suspicious mid-cycle changes, and year-end scams.
Employer's Guardian helps employers build and run these controls as part of payroll services, including change verification procedures, approval workflows, and reconciliation practices that catch fraudulent changes before funds move.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.