Payroll Diversion Fraud
An email from an employee asks HR to change where their salary is paid. It is a fraudster. How payroll diversion works and the checks HR and payroll teams should use.

Payroll diversion is quiet and effective. A short, polite email from an employee asks HR to update their bank account before the next payday. The employee never sent it, and their salary goes to a fraudster.
How it happens
- Emails from lookalike or personal addresses using an employee's name. See checking the sender.
- A hacked employee email account. See signs email is hacked.
- Phishing for employee self-service logins. See HR phishing.
Checks that stop it
- Never change bank details based on email alone.
- Confirm in person or by phone using contact details already on file.
- Use a self-service payroll system with two-step verification.
- Notify the employee through a second channel when details change.
Timing is a clue. Requests just before payroll leave little time for checks. That is deliberate.
For more, see our guide to business cybersecurity.
Frequently asked questions
How do fraudsters know who to impersonate?
Names and roles are often on company websites and professional profiles. Some use a hacked employee email account.
What is the best check?
Confirm changes in person or by phone with the employee using contact details already on file, not details in the request.
Can employees change details themselves securely?
Yes, through an HR or payroll system with two-step verification, which is safer than email requests.
Sources
- Cybersecurity for Small Business, US Federal Trade Commission
- Phishing attacks: defending your organisation, UK National Cyber Security Centre
- Internet Crime Complaint Center, FBI


