SardineCon SF/2026

Learn More
Scams & social engineering4分 で読めます

Payroll diversion scamとは?

ニュースレターを購読

A payroll diversion scam phishes an employee's HR or payroll login to redirect their salary direct deposit into a fraudster's account. The paycheck lands in the attacker's account on payday, and the employee often does not notice until the money they were counting on never arrives.

What is a payroll diversion scam?

Payroll diversion is account takeover aimed at a paycheck. The attacker phishes an employee for their credentials to the company's HR, payroll, or self-service portal, logs in as that employee, and quietly changes the direct-deposit bank details to an account they control. On the next pay run, the salary is routed to the fraudster instead of the employee.

The entry point is usually a phishing email or fake login page imitating the payroll or HR system. Because the attacker only needs to change one field, the direct-deposit account, the change is small, easy to miss, and often made just before payday to minimize the window for anyone to notice.

For fraud teams, the useful framing is that this is business email compromise pointed at employees rather than vendors. Instead of redirecting a supplier invoice, the attacker redirects wages, and the receiving account is typically a mule or a newly opened account built to catch a single deposit and move it on.

How a payroll diversion scam unfolds

The scam turns one stolen login into a redirected paycheck:

  1. PhishSteal the login A fake HR or payroll email lures the employee to a lookalike page that captures their credentials.
  2. AccessLog in as the employee The attacker enters the self-service portal and reviews the pay and direct-deposit settings.
  3. RerouteChange the deposit account They swap the bank details for a mule account, often just before the pay run closes.
  4. CollectTake the paycheck Payday sends the salary to the fraudster, who withdraws or forwards it before it is noticed.

Who is involved?

Who

Their role

The attacker

Phishes the employee, changes the deposit details, and controls the receiving account.

The employee victim

Loses a paycheck when their salary is routed away, often noticing only when pay fails to arrive.

The employer and payroll system

Processes the changed instruction in good faith and must sort out the shortfall and reissue pay.

The receiving bank

Holds the mule account that catches the diverted salary and where the funds are cashed out.

What it looks like in practice

An employee receives an email that appears to come from the HR system, warning that their direct-deposit details must be reconfirmed to avoid a delay in pay. The link opens a page that looks like the company portal, and the employee enters their username and password.

Days later, an attacker uses those credentials to log in and update the direct-deposit account to one they control, timed just before the pay run. On payday the salary lands in the new account and is withdrawn within hours. The employee only realizes when their expected pay never shows, by which point the receiving account has been emptied.

Why it matters for operators

Payroll diversion is quiet and precise. It touches a single field rather than initiating an obvious payment, so it slips past controls tuned to watch for new payees or large transfers. And the harm is concentrated: for the employee, it is a whole paycheck gone, often right when rent or bills are due.

The bank that holds the receiving account is well placed to catch it, because a normal personal account that suddenly receives a payroll-sized ACH credit from an employer it has no relationship with, then immediately sweeps it out, is a clear mule pattern. Employers reduce exposure by requiring out-of-band confirmation for direct-deposit changes and alerting employees whenever bank details are updated, which shortens the window an attacker has to exploit.

What to watch in the data

  • Payroll credit to a mismatched account. An employer ACH salary payment landing in a personal account with no prior relationship to that employer.
  • Deposit change then payday. A direct-deposit detail updated shortly before a pay run, especially from a new device or location.
  • Fast sweep-out. A newly received salary withdrawn or forwarded within hours, leaving little balance behind.
  • Portal login anomalies. HR or payroll self-service logins from unfamiliar devices, IPs, or geographies preceding a details change.
  • Clustered targeting. Multiple employees at one company changing deposit details in a short window, pointing to a phishing wave.

Quick questions

How does the attacker get into the payroll portal?

Usually by phishing the employee with a fake HR or payroll email that leads to a lookalike login page. The harvested username and password are then used to sign in to the real self-service system.

Why change the details right before payday?

To shrink the window for detection. Making the change close to the pay run means the salary is diverted before the employee or employer is likely to review deposit settings.

Who loses the money?

It varies. Employers often reissue the pay so the employee is made whole, which shifts the loss to the company, though outcomes depend on timing, recovery, and internal policy.

How is this related to business email compromise?

It is the same idea aimed at wages instead of vendor invoices. Rather than redirecting a supplier payment, the attacker redirects an employee's salary by altering direct-deposit details.

What is the most effective employer control?

Require out-of-band verification for any direct-deposit change and send an automatic alert to the employee whenever bank details are updated, so an unauthorized change is caught quickly.

Can a bank spot the receiving account?

Yes. A personal account receiving a payroll-sized credit from an unrelated employer and immediately sweeping it out fits a mule profile and is a strong candidate for review.

Payroll diversion scamと併せて知っておきたい用語

レポート

2026年 不正・AMLレポート

予測は不要です。このレポートは、不正・AMLチームが実際に直面していることと、その対応方法を分解して解説します。

レポートをダウンロード