Payroll Direct Deposit Scams: How to Verify a Paycheck Change Request

Payroll Direct Deposit Scams: How to Verify a Paycheck Change Request

Payroll scams are quiet because they do not usually start with a dramatic threat. They start with something routine: a short email from an employee, a message that looks like it came from HR, or a form asking to update direct deposit information.

That is what makes them dangerous.

The attacker is not trying to hack the bank first. They are trying to hack the process around the bank: trust, speed, inbox overload, and the habit of treating payroll changes as normal administrative work.

For small businesses, one fake direct deposit change can turn into a missed paycheck, an angry employee, a messy bank recovery process, and a hard lesson in verification.

How the scam works

A typical direct deposit scam follows a simple pattern:

  1. The scammer impersonates an employee, contractor, executive, or HR vendor.
  2. They send a polite request to change bank details before the next payroll run.
  3. They provide a new routing number, account number, or payroll portal link.
  4. The payroll contact updates the record without calling the person directly.
  5. The next paycheck goes to the scammer-controlled account.

The email may not look sloppy. It may use the employee's name, title, signature style, and normal work tone. If the business uses predictable email formats, public staff pages, LinkedIn, or vendor directories, the attacker can make the request look boringly real.

And boring is the point.

Red flags in payroll change requests

Be cautious when a payroll or banking change includes any of these signals:

  • The request arrives right before payroll cutoff
  • The sender says they cannot talk by phone
  • The employee asks to use a new bank immediately
  • The email address is close, but not exact
  • The message comes from a personal email account
  • The request uses unusual grammar or tone for that person
  • The requester asks you to ignore normal approval steps
  • The bank account belongs to a digital wallet, prepaid provider, or unfamiliar institution
  • A link asks the employee or payroll manager to log in and "confirm" details

No single red flag proves fraud. But payroll should not move on vibes. It should move on verified identity.

The rule that stops most of it

Use an out-of-band verification rule for every direct deposit change.

That means: do not verify the change by replying to the same email, clicking the same link, or texting the number inside the request.

Instead, use a known contact method already on file. Call the employee's existing phone number. Message them through the company system. Confirm in person if possible. For remote teams, use the employee's established work chat or HR platform login, not the contact details supplied in the change request.

The script can be simple:

"I received a request to change your direct deposit. Did you send it, and should payroll update the account ending in 1234?"

Do not read back the full account number. Do not accept "yes" from a new number. Confirm enough to validate the request without spreading sensitive details.

What employees should know

Employees can help by treating payroll information like a high-value credential.

They should:

  • Send payroll changes only through the approved HR or payroll system
  • Avoid emailing full bank details whenever a secure portal exists
  • Report suspicious HR or payroll messages immediately
  • Use strong, unique passwords on payroll and email accounts
  • Turn on multi-factor authentication for payroll portals
  • Watch for paycheck deposit failures or unexpected payroll notifications

If an employee receives a message saying their payroll account was changed, they should not click links in that message. They should go directly to the payroll provider's official site or contact the company payroll person through a known channel.

What small businesses should change

The best payroll security is not complicated. It is consistency.

Create a written policy that says:

  • Direct deposit changes must go through one approved channel
  • Every bank change requires out-of-band confirmation
  • Payroll staff cannot waive verification because a request feels urgent
  • Bank detail changes after a cutoff date wait until the next payroll cycle unless reviewed by a manager
  • New account details are checked before the next pay run
  • Suspicious requests are saved and reported internally

Then make the policy normal. If everyone knows a quick call is required, the call stops feeling suspicious or inconvenient. It becomes just how payroll works.

If you already changed the deposit

Move fast.

  1. Contact the payroll provider and bank immediately.
  2. Tell the affected employee what happened.
  3. Preserve the email, headers, phone numbers, links, and attachments.
  4. Reset passwords for any account that may have been accessed.
  5. Review other recent payroll or vendor banking changes.
  6. File reports with the bank, payroll provider, and appropriate fraud channels.

Recovery depends on timing. The sooner the issue is reported, the better the odds of stopping or tracing the transfer.

A simple verification checklist

Before approving any payroll bank change, ask:

  • Did the request come through the approved system?
  • Have we confirmed the request through a known channel?
  • Does the employee recognize the new account?
  • Is the timing unusual or rushed?
  • Did anyone ask us to bypass the normal process?
  • Is there a second reviewer for the change?

If the answer feels messy, pause the update.

Payroll mistakes are expensive because they are personal. A stolen paycheck is not an abstract business loss. It is rent, groceries, car payments, and trust.

The fix is not paranoia. It is a boring rule applied every time: no direct deposit change without independent verification.

🔍 Think You've Been Targeted?

Use our free AI-powered scam detector to analyze suspicious messages, emails, or screenshots instantly.

Check for Scams — Free