Payroll impersonation is a fraud technique in which an attacker poses as someone with legitimate standing to direct payroll activity — an employee, an executive, a payroll vendor, or a member of the finance team — in order to obtain money or data. It is the connective tissue across most payroll fraud, because nearly every scheme begins with the attacker convincing someone they are somebody else.

What varies is who is impersonated and what is requested. The underlying weakness is constant: a process that accepts identity claims without verifying them.

The four impersonation targets

The employee. The attacker poses as a worker requesting a direct deposit change. This is the most common variant and the one that produces payroll diversion. It requires only a name and employer, both usually available publicly.

The executive. The attacker poses as a CEO or CFO, typically requesting employee data or an urgent off-cycle payment. Authority plus urgency is the operative combination, and it works because questioning a senior person feels professionally risky.

The payroll vendor. The attacker poses as the employer's payroll provider, requesting credentials, asking the employer to confirm details, or announcing a change in banking arrangements. This variant is effective because employers rarely verify inbound contact from vendors they already work with.

Internal finance or HR staff. The attacker poses as a colleague to obtain information or to get a change processed, often by referencing real internal details gathered from a compromised mailbox or public sources.

Why sender-based checks fail

Employers commonly train staff to check the sender address. That helps against the crudest attempts and fails against the ones that matter.

Lookalike domains survive casual inspection — a single transposed character in a familiar name is not noticed by someone processing dozens of requests. Display names can be set to anything. And in the most difficult case, the attacker has compromised a genuine mailbox, so the message arrives from the real address with real signature blocks and real conversation history.

That last scenario defeats every check based on what the message looks like. It is also increasingly common, because credential theft is cheap and a compromised mailbox is a durable platform for fraud.

The conclusion is that identity cannot be established from the message. It has to be established through a separate channel.

Verification that works

The rule is out-of-band confirmation using contact details the organization already holds, not details supplied in the request.

For an employee request, that means calling the number in the HR system. For an executive request, calling the executive's known number or confirming in person. For a vendor contact, calling the account contact already on file — never a number in the email signature, which the attacker controls.

Applied consistently, this defeats all four impersonation variants including the compromised-mailbox case, because the attacker cannot intercept a call to a number they did not supply.

The social obstacle

The barrier to this control is almost never technical understanding. It is that verifying feels like an accusation, and verifying a senior person feels like insubordination.

Attackers rely on this precisely. Executive impersonation works because the recipient weighs the cost of being wrong about a fraud against the cost of appearing to distrust the CFO, and the second feels more immediate.

The countermeasure is organizational rather than procedural. Leadership must state explicitly that verification is expected, that it applies to them, and that no one will face any consequence for verifying a request that turns out to be genuine. Where executives have said this clearly and publicly, staff verify. Where they have not, the policy exists on paper and is abandoned under pressure.

The rule also needs to be absolute. Any exception — for seniority, for urgency, for a particular relationship — reintroduces the judgment call the attacker is trying to influence.

Supporting controls

  • Defined channels for banking changes and data requests, so anything arriving outside the normal route is visibly abnormal
  • Waiting periods on banking changes, which remove the urgency the schemes depend on
  • Two-person approval for payment and banking changes
  • Notification to the affected party through existing contact details whenever a change is made
  • Vendor contact records maintained independently, so a claimed vendor contact can be checked against something the attacker did not provide
  • Multi-factor authentication on mailboxes, which reduces how often the compromised-account variant is available at all

Detection and response

Impersonation campaigns rarely target a single person. An attempt against one employee usually means others received similar messages, and a quick check across the payroll and finance functions after any suspected attempt frequently surfaces more.

Where an attempt succeeded through a compromised internal mailbox, the response has to extend beyond the transaction. The account itself needs remediation, and the attacker's access to whatever that mailbox contained has to be assessed — often a larger problem than the payment that prompted the investigation.

Employer's Guardian helps employers establish verification standards and change controls across payroll operations through payroll services.

This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.

Let's Talk! Schedule a Conversation

For additional information, pricing, and/or free consultation, contact us. We'd be happy to discuss your situation.

Contact Us Today!

Want a professional to walk you through your HR needs shopping list?

At Employer’s Guardian, our experts are here to help. We are happy to work with you to understand your HR needs. Get in touch—give us a call or fill out our online contact form and we’ll promptly get back to you!

Contact Us Today!