HR News | Employer's Guardian

Payroll Diversion: What Employers Need to Know

Written by Admin | Aug 18, 2026, 3:39:05 PM

Payroll diversion is a fraud scheme in which an attacker reroutes an employee's wages to an account they control. It rarely involves breaking into a payroll system. In most cases the attacker simply asks someone in HR or payroll to update a direct deposit record, and the request looks close enough to routine that it gets processed.

For employers, this is one of the few fraud types where the loss lands directly on the workforce. An employee works a full pay period and receives nothing, while the money settles into a prepaid card or a short-lived checking account and is withdrawn within hours. The employer then has to decide whether to make the employee whole, which in practice they almost always do.

Why payroll diversion targets HR, not IT

Attackers go where the authority sits. The ability to change where an employee's money goes is held by payroll administrators and HR staff, not by the security team. That makes payroll one of the highest-value targets in an organization while often being one of the least hardened, because the controls around it are procedural rather than technical.

The scheme also exploits a real tension in HR work. HR teams are measured on being responsive and helpful to employees. A request that says "I switched banks and need my deposit updated before Friday" is exactly the kind of request a good HR professional wants to resolve quickly. The attacker is counting on that instinct.

How the scheme typically unfolds

A common sequence looks like this. The attacker identifies an employee through a public source such as a professional networking profile or a company directory. They register a lookalike email address, often changing a single character or using a free email provider with the employee's real name. They send a message to HR or payroll asking to update direct deposit details, sometimes attaching a filled-out form pulled from the employer's own public website.

If the request is processed without an independent verification step, the change takes effect on the next payroll run. The fraud is usually discovered only when the employee reports a missing paycheck, which means the loss is already several days old and the funds are gone.

A more advanced version begins with a compromised employee email account. In that case the request arrives from the genuine address, which defeats any check based on matching the sender. This is why verification has to happen through a separate channel rather than by replying to the message.

Warning signs worth training staff to catch

  • Urgency tied to a payroll deadline, particularly requests arriving in the final day or two before processing closes
  • A new email address, or a reply-to address that differs from the sender address
  • Reluctance to take a phone call, or a phone number supplied in the request itself rather than one already on file
  • Bank details for a prepaid card issuer or an institution with no branch presence in the employee's area
  • A change request that arrives alongside other profile updates, such as a new mailing address or phone number, which is often an attempt to defeat later verification
  • Multiple change requests for different employees within a short window

Controls that actually stop it

The single most effective control is out-of-band verification. Any change to direct deposit information should be confirmed by contacting the employee through a channel already on file, using a phone number retrieved from the HR system rather than one provided in the request. This one step defeats both the lookalike-address version and the compromised-account version of the scheme.

Beyond that, a small number of procedural controls carry most of the weight:

  • A mandatory waiting period. Holding banking changes for one full pay cycle removes the urgency the scheme depends on.
  • Two-person approval. Requiring a second reviewer for any banking change means a single compromised or rushed employee cannot complete the fraud alone.
  • Change notifications. Automatic alerts to the employee's address of record whenever banking details change give the real employee a chance to flag an unauthorized update before payday.
  • Pre-run reconciliation. Reviewing all banking changes made since the previous cycle, as a discrete step before payroll is finalized, catches changes that slipped through.
  • Restricting who can make the change. Limiting banking edits to a named set of payroll administrators reduces the number of people an attacker can target.

What employers owe the employee

Wage payment obligations do not disappear because a third party intercepted the funds. In most circumstances an employer that pays a fraudulent account has not satisfied its obligation to pay the employee, which means the employer absorbs the loss and still owes the wages. In California, late or unpaid wages can also raise exposure under state wage payment rules, which is why payroll diversion is worth treating as a compliance issue rather than purely a fraud issue.

Recovery is possible but time-sensitive. If the fraud is caught within a day or two, the receiving bank can sometimes freeze the funds. After that the money is usually unrecoverable, which is why detection speed matters more than any post-incident process.

Where this fits in a broader payroll control set

Payroll diversion is one expression of a wider problem: payroll processes that were designed for convenience rather than for verification. Employers that tighten change verification generally find the same controls also address related schemes such as payroll impersonation, suspicious mid-cycle changes, and year-end scams.

Employer's Guardian helps employers build and run these controls as part of payroll services, including change verification procedures, approval workflows, and reconciliation practices that catch fraudulent changes before funds move.

This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.