How the scheme usually works
Payroll diversion fraud is a form of business email compromise. Someone impersonates an employee, sometimes using a lookalike email address or a hacked account, and asks HR or payroll to change bank information. In other cases, attackers gain access to an employee self-service portal and make the change directly. The diverted pay is often moved quickly out of the receiving account, so the first hours after discovery are important. Fraudsters often time the request just before a pay cycle so that the change takes effect before anyone notices.
Responding when pay has been diverted
Contact your bank and payroll provider right away to request a reversal or recall of the payment, and report the fraud to law enforcement and the FBI's Internet Crime Complaint Center. Secure affected email accounts and portals, reset credentials, and review whether other employees' data was accessed or changed. Keep the fraudulent emails in their original form, along with logs and records of the change. Wage-payment laws generally still require the employee to be paid on time, and the loss usually cannot be taken out of later pay, so arrange that pay without waiting for recovery.
Questions that follow the incident
We look at whether a data breach notification obligation is triggered, whether the employer's crime or cyber insurance covers social engineering losses, and what notice the insurer requires. We also review internal procedures, such as verifying bank changes through a known phone number, and whether a vendor or payroll provider shares responsibility. If an employee is suspected of involvement, we discuss how to investigate without overstepping. The aim is to address the immediate loss and reduce the chance that the same weakness is exploited again.