If a payroll deposit change was requested in your name and you didn’t authorize it, you’re likely the target of a fast-moving fraud attempt designed to reroute your paycheck to a criminal’s account. Time matters. The sooner you act, the higher your chance of stopping or reversing the transfer and preventing additional harm. This guide explains what’s happening, the exact steps to take in the first 24–48 hours, how to secure your accounts and identity, and how to reduce your exposure to future attacks.
How Payroll Deposit Redirection Fraud Works
Fraudsters try to convince your employer’s payroll team to change your direct deposit details to an account they control. They commonly use:
- Phishing or business email compromise (BEC): Criminals impersonate you via a spoofed email or by taking over your email account to request a deposit change.
- Fake HR portals: You’re tricked into entering your credentials on a lookalike payroll site; they then change your bank details.
- Social engineering: A phone call claims “urgent banking issues” and pushes payroll to override normal procedures.
- Insider or third-party compromise: Someone with access to payroll systems alters your record.
Signs include HR contacting you about a change you didn’t request, notifications from your payroll system, or a missing/short paycheck. Treat any such signal as a serious incident, even if funds haven’t moved yet.
Take These Steps Immediately (First 24 Hours)
- Call your payroll/HR department right now. Say the request was unauthorized and ask them to:
- Freeze any pending deposit change and revert to your previous account on file.
- Reject or cancel any new account details not confirmed by you in person or via a known secure process.
- Document the incident and notify internal security or IT.
- If payday already processed, ask payroll and your bank to initiate a recall. Provide details of the fraudulent account and the deposit date. Same-day or next-day action has the best chance of recovery.
- Change passwords for your work and personal email immediately. Prioritize any account used for payroll, HR, or benefits. Use unique, strong passwords via a reputable password manager.
- Turn on multi-factor authentication (MFA) everywhere possible. Prefer app-based or hardware-key MFA over SMS when available.
- Secure your devices. Update operating systems and browsers, run a reputable anti-malware scan, and remove suspicious extensions.
- Alert your manager or security team. They may need to review logs, block suspicious IPs, and enforce stricter payroll-verification steps.
What to Tell Payroll (Exact Talking Points)
Be clear and concise. Provide:
- Your full name, employee ID, and contact details.
- Statement: “I did not authorize any change to my direct deposit information.”
- Date/time you or HR noticed the request and how it was received (email, portal, phone).
- Any suspicious emails, caller IDs, or links you received.
- Your current, correct deposit information on file (verify in person or through a known secure channel).
- Request for confirmation once the account is locked and reverted, and for written incident documentation.
If Your Paycheck Was Diverted
- Ask payroll to file an ACH recall immediately. Time-sensitive. The receiving bank may freeze the funds if contacted quickly.
- Contact your bank or credit union’s fraud department. Explain that payroll redirection fraud occurred; ask them to monitor for unusual activity and help with any necessary affidavits.
- File a police report. Having a report number can help with bank, employer, and insurer processes.
- Report the incident to the FTC at IdentityTheft.gov. Complete an identity-theft report and recovery plan. This can support further disputes.
- Consider a temporary advance from your employer. Some organizations offer emergency advances when payroll fraud strikes.
Lock Down the Likely Entry Points
Most payroll-change scams begin with account compromise. Reduce the risk with these steps:
- Email accounts: Change passwords, enable MFA, check forwarding rules and recovery addresses for tampering, and review recent login locations.
- Work accounts: Notify IT, reset SSO credentials, and re-enroll MFA. Ask for a review of access logs.
- Payroll/benefits portals: Reset passwords, enable MFA, and verify your personal and banking details are correct.
- Phone number and SIM: Add a carrier account PIN/port-freeze to stop SIM swapping, which can bypass SMS codes.
- Security questions: Replace guessable answers with password-manager–stored phrases.
Preserve Evidence
Keep records; they help investigations and recovery attempts:
- Save suspicious emails with full headers and any attachments.
- Take screenshots of portal notifications, messages, and changed account details.
- Log dates, times, names, and case numbers for every call.
- Keep copies of police and FTC reports.
Notify and Protect Beyond Payroll
Criminals who try to redirect your paycheck may also attempt identity theft, tax fraud, or credit abuse. Strengthen protections across your financial identity:
- Place a free fraud alert with one major credit bureau; it will notify the others. This requires creditors to take extra steps to verify you for new credit.
- Consider a credit freeze with each bureau if you’re not applying for credit soon. A freeze blocks most new-credit pulls in your name until you lift it.
- Monitor your accounts for unfamiliar transactions and new-account inquiries.
- Protect tax identity: Create or secure your IRS and state tax accounts and consider an IRS IP PIN to prevent fraudulent tax returns filed in your name.
How Employers Can Help (Share with HR)
If you’re in HR or payroll, tightening controls reduces risk for everyone:
- Out-of-band verification: Require live, known-number phone verification or in-person confirmation for any deposit change.
- Two-person approval: Implement dual control for payroll changes, especially close to pay cycles.
- Delay activation: Apply a short waiting period and send automatic alerts for changes.
- Anti-phishing training: Teach staff to spot lookalike domains and urgent payment requests.
- Secure email: Enforce MFA, disable legacy protocols, and monitor for suspicious forwarding rules.
- Incident playbooks: Maintain step-by-step procedures for recalls, legal notifications, and employee support.
Red Flags to Watch For
- “Urgent” requests to update bank details right before payroll cutoff.
- Emails from lookalike domains (e.g., jon.doe@company-payroll.co instead of company.com).
- Requests to bypass normal verification due to “travel,” “phone issues,” or “system outages.”
- Unusual MFA prompts or password-reset notifications you didn’t initiate.
- HR portal alerts about contact or deposit changes you didn’t make.
Frequently Asked Questions
Will this show up on my credit report?
Direct-deposit redirection generally does not appear on your credit report because it involves payroll and bank transfers, not a new credit account. This is one reason certain fraud goes undetected by credit-only tools. For more on why some incidents won’t surface in your file, see: Why Can Fraud Happen Without Appearing on Your Credit Report?
Can credit monitoring help with payroll fraud?
Credit monitoring can’t stop a payroll transfer, but it can alert you to related identity abuse—like unauthorized credit applications that often follow an account compromise. To understand where it helps and where it doesn’t, read: Can Credit Monitoring Catch Fraud Before It Damages Your Credit?
Should I close my bank account?
If your own bank account was replaced with a criminal’s account at payroll but your bank itself wasn’t compromised, you usually don’t need to close your account. If you see signs of account takeover (unknown transfers, new payees you didn’t add), work with your bank’s fraud team; they may recommend closing and reopening.
What if someone changed my home address or phone in the payroll system?
Ask HR to revert those details, lock the account, and require re-verification for all profile changes. Update your security settings and investigate possible email or device compromise.
Could this be part of a bigger breach?
Possibly. If multiple employees are affected, your company may be dealing with a phishing campaign or vendor compromise. Encourage coordinated incident response, including IT forensics and employee-wide credential resets.
Build Longer-Term Protection
- Use a password manager to create unique credentials for email, payroll, and banking.
- Enable MFA on financial, email, and employer systems; prefer app-based codes or security keys.
- Reduce public exposure of personal details (emails, phone numbers) that help attackers answer verification questions.
- Beware of W-2 phishing seasonally—tax-time scams often target payroll and HR for employee data.
- Review account alerts for profile changes, new devices, and sign-ins from unfamiliar locations.
Next Steps to Stay Informed
After you’ve contained the incident, consider tools that help you watch for new risks across your financial identity. Ongoing monitoring can provide early warnings when your information is used in ways that could impact your credit and finances. If you want to evaluate an integrated option, you can review SmartCredit as an optional next step: SmartCredit for privacy, credit monitoring, and identity protection.
Conclusion
An unauthorized payroll deposit change is a high-priority red flag for account compromise and identity fraud. Act immediately: lock down the change with HR, attempt an ACH recall if funds moved, reset passwords, enable MFA, and secure your devices and accounts. Preserve evidence, file the appropriate reports, and strengthen your broader identity protections with alerts, freezes, and careful monitoring. Quick action can prevent paycheck loss today and stop deeper identity abuse tomorrow.
Good to Know
Payroll-change fraud often starts with a single compromised email account. Even if your paycheck still arrived correctly, treat any unauthorized change request as a high‑risk incident and secure your accounts immediately.