Payroll scams are fraud schemes that either divert an employee’s paycheck to a criminal-controlled bank account or steal bulk employee tax data for identity theft, and they succeed by exploiting the humans in your payroll process rather than the software. The window for recovering stolen wages is measured in hours, so recognizing the pattern and having a verification habit already in place matters far more than any single technical control.
The Main Types You’ll Encounter
Three variants account for most of the payroll fraud businesses see.
Direct deposit diversion is the most financially damaging. A fraudster impersonates an employee by email and asks payroll or HR to “urgently” update the direct deposit information on file. If the change goes through, the employee’s entire net pay lands in the fraudster’s account on the next pay cycle. Nobody notices until payday.
W-2 phishing aims wider. Instead of one paycheck, the attacker wants Social Security numbers, income figures, and home addresses for every employee at once. The email usually appears to come from the CEO or another senior executive and demands copies of all employee W-2 forms for an “audit” or tax filing. A single successful attack can compromise hundreds or thousands of employees, and the stolen data feeds fake tax returns, new credit accounts, and dark-web sales.
Ghost employee schemes are internal. Someone with payroll system access adds fictitious workers to the roster and routes their paychecks to accounts they control. These schemes flourish where one person handles both data entry and payment approval. Audit red flags include multiple employees sharing a bank account, workers with no performance reviews or email activity, former employees still on the payroll, and temporary workers whose names were never removed after their contracts ended.
How a Diversion Attack Actually Unfolds
The sequence is predictable, and knowing it tells you exactly where to intervene.
The fraudster starts with research. LinkedIn and the company website give them the names and titles of payroll staff, HR contacts, and executives. They learn the company’s email format and pick whose identity to steal. Then they craft a personalized email that appears to come from that real person. The sender address is typically one letter off from the real domain, something a reader in a hurry won’t catch.
The message requests an immediate direct deposit change, complete with new routing and account numbers. The pretext varies but always carries urgency: a closed bank account, a mortgage closing, a switch to a new bank that “needs to be done before Friday’s payroll.” Almost every one of these emails includes a specific instruction to handle the request by email only, because the sender is supposedly traveling, in meetings, or otherwise unreachable by phone. That instruction is the entire attack. It blocks the one step that would stop everything: a verification call to the real employee.
If payroll processes the change without calling, the next cycle deposits the wages into a mule account, and the fraudster moves the money out within hours. Under NACHA rules, an employer has only five banking days after the settlement date to initiate an ACH reversal, and that assumes the receiving bank still has funds to freeze.
Warning Signs to Train Your Team On
Most payroll scams share a small set of tells. Teaching payroll and HR to pause on these is worth more than any tool.
- Unusual urgency tied to the next payroll run. Real employees rarely treat a routine bank change as an emergency.
- Insistence on email-only communication and explicit discouragement of phone calls. This is the single biggest red flag in a diversion attempt.
- Requests to keep the change confidential or “between us.” Genuine employees don’t care who in HR knows they switched banks.
- Subtle domain differences, like “company-hr.com” instead of “companyhr.com,” or swapped similar characters.
- Executive pressure for bulk W-2 data. Actual executives almost never request this by email, and legitimate audits don’t run on same-day timelines.
- Formatting inconsistencies: unusual greetings, off-template signature blocks, phrasing that doesn’t sound like the person being impersonated.
The response to any of these is the same. Stop, and call the person at a number already on file. Never a number from the suspicious email.
Controls That Actually Stop Payroll Fraud
Mandatory Verbal Verification
Every request to change an employee’s bank account, home address, or tax withholding should require a verbal confirmation before processing. The call goes to a number already in company records, never one provided in the change request. Confirm something a fraudster wouldn’t know, like the employee’s date of hire or department. Any change request received solely by email is suspicious until verified.
Separation of Duties
No single person should control the entire payroll pipeline from data entry through payment approval. One person in HR enters employee changes, a finance manager approves the payroll run, and a separate accounting team member reconciles payments afterward. This layered structure is what makes ghost employee schemes so much harder to run, because the person adding a fake employee isn’t the same person approving the payment.
Access Controls and Authentication
Multi-factor authentication should be mandatory for every account that touches payroll software. SMS-based codes are better than passwords alone but remain vulnerable to interception. Hardware security keys using the FIDO2 standard are significantly stronger.
Beyond authentication, apply least privilege: each user gets only the minimum access their role requires. Review access logs for logins at odd hours or from unexpected locations. Every device that connects to payroll should run current endpoint protection.
Focused Training and Simulations
Generic phishing awareness isn’t enough for the people who handle payroll. Payroll and HR staff need training aimed specifically at diversion and W-2 attacks, including simulated phishing emails that mimic real ones. Run the simulations periodically and track who follows the verification protocol. Give staff a clear internal channel for flagging suspicious requests without worrying about looking foolish if the request turns out to be legitimate. The goal is a team that defaults to skepticism when money is involved.
What to Do in the First Hours After a Payroll Scam
Speed matters more than anything else. Every step below should happen in parallel, not in sequence.
Call the Banks
Contact your company’s bank immediately to report the fraudulent transfer and request a recall. NACHA rules give an employer five banking days from the settlement date to initiate an ACH reversal, but recovery odds fall sharply with each passing hour as fraudsters drain mule accounts. Contact the receiving bank as well if you have its information, and ask for a temporary hold. Provide the transaction amount, date, and a clear statement that the transfer was fraudulent.
Lock Down Compromised Accounts
Reset passwords and revoke access for every account involved: the affected employee’s credentials, the payroll administrator’s login, and any supervisor accounts. Have IT review access logs for unauthorized logins or administrative changes made around the time of the fraud. If the attacker got into the payroll platform itself rather than just spoofing an email, assume all employee data in the system may be compromised.
Report to Federal Authorities
File a complaint with the FBI’s Internet Crime Complaint Center (IC3), the central federal hub for cyber-enabled fraud. Include transaction amounts, account numbers, email headers from the spoofed message, and a timeline. The FBI’s Recovery Asset Team uses IC3 filings to coordinate with financial institutions on freezing funds in domestic accounts.
If the scam involved W-2 data, IRS reporting splits into two tracks. If your company actually sent employee W-2 data to the scammer, email dataloss@irs.gov with the subject line “W2 Data Loss.” Include your business name, EIN, a contact name and phone number, a summary of how the breach occurred, and the number of employees affected. Do not attach any employee data. Also forward the phishing email itself to phishing@irs.gov with the subject line “W-2 scam,” noting that your company was a victim. If your company received the phishing email but did not send any data, forward it to phishing@irs.gov without the extra reporting.
Email the Federation of Tax Administrators at statealert@taxadmin.org as well. They coordinate reporting to state tax agencies.
Protecting Employees Whose Data Was Exposed
When employee data is compromised, obligations to employees don’t end at federal reporting. Affected workers need direct notification and practical guidance.
Credit Freezes
Anyone whose Social Security number was exposed should place a credit freeze with Equifax, Experian, and TransUnion. Federal law makes freezes free. When requested online or by phone, the bureau must place the freeze within one business day and lift it within one hour when the employee wants to apply for credit. A freeze blocks creditors from accessing the file, making new-account fraud far harder.
IRS Identity Protection
Employees whose W-2 data was stolen face the specific risk of fraudulent tax returns filed in their name. They should file IRS Form 14039, the Identity Theft Affidavit, if they believe they’re victims of tax-related identity theft and haven’t already received an IRS verification letter. The form can be completed online and mailed or faxed, or submitted through IdentityTheft.gov.
Once confirmed, the IRS marks the account and issues an Identity Protection PIN each year. Employees don’t have to wait for confirmed fraud, though. Anyone with a Social Security number can proactively enroll in an IP PIN through their IRS online account. The six-digit number is required on the tax return, so a fraudster without it can’t file a fake one.
State Notification Requirements
All 50 states have data breach notification laws requiring businesses to tell affected individuals when their personal information is compromised. Deadlines generally fall between 30 and 60 days after discovery, and many states also require notification to the state attorney general. Because requirements differ by jurisdiction, a breach affecting employees in multiple states usually needs legal counsel to sort out each state’s timeline and disclosure obligations.
Insurance Coverage Isn’t Automatic
Standard commercial general liability insurance almost never covers payroll fraud losses. The relevant coverage sits in two specialized policy types: cyber insurance and commercial crime insurance. Both deserve close reading before you need them.
Cyber policies often include coverage labeled “computer fraud,” “funds transfer fraud,” or “fraudulent instruction.” For a typical diversion scam where an employee is tricked by a spoofed email, the applicable coverage is usually “fraudulent instruction,” but the exact label and scope vary between carriers. Crime policies may also cover social engineering losses, though sometimes only through a specific endorsement rather than by default.
Two limitations catch businesses off guard. First, social engineering coverage is frequently subject to sublimits far lower than the overall policy limit. A policy with a $5 million aggregate might cap social engineering claims at $250,000. Second, many policies require the insured to maintain specific verification procedures, such as callback authentication, before transferring funds. If your company didn’t follow those procedures when the fraud occurred, the insurer can deny the claim. Your internal controls aren’t just good practice; they may be a contractual condition of coverage.
The Third-Party Payroll Provider Problem
Outsourcing payroll doesn’t outsource the liability. The IRS warns that some third-party providers have failed to submit client payroll taxes or shut down abruptly. When that happens, the employer typically remains legally responsible for the unpaid taxes, even if it already sent the money to the provider. Using a payroll service does not shift tax liability.
The exception is a certified professional employer organization, which assumes sole liability for paying employment taxes, filing returns, and making deposits related to the wages it handles. A standard reporting agent, by contrast, is required to remind clients in writing that the employer, not the agent, bears ultimate responsibility for timely filing and payment.
Before hiring a provider, verify their credentials, check the Better Business Bureau, and confirm that tax deposits are actually reaching the IRS by monitoring your account through the Electronic Federal Tax Payment System. If a provider is ever compromised, treat it with the same urgency as an internal breach: lock down access, notify affected employees, and report to the IRS and IC3.