If a company you trust suffers a data breach and your direct-deposit instructions are exposed, it can put your incoming paychecks, government benefits, and tax refunds at immediate risk. Criminals use exposed bank account numbers, routing numbers, and payroll-portal details to reroute deposits, impersonate you with HR, or socially engineer your employer’s payroll team. The good news: with quick, methodical steps, you can shut down the most likely attack paths and keep your income safe.
What “Direct-Deposit Instructions” Usually Include
Direct-deposit instructions typically include the bank name, routing number, account number, and account type used for ACH transfers. In some workplaces or platforms, they may also include your payroll portal username, a masked email, or phone number. Even if your full Social Security number was not exposed, criminals can still attempt to:
- Submit a direct-deposit change request to your employer or benefits provider.
- Use exposed banking details for social-engineering attempts.
- Target your payroll portal with password-reset or takeover tactics.
- Reroute your tax refund by changing deposit details on your tax account or return.
Act Immediately: First 24–48 Hours
Move quickly. Your goal is to block rerouting attempts before the next payroll cycle or benefit payment.
- Notify your employer’s payroll or HR department right away. Tell them your direct-deposit details were exposed in a breach and request a temporary hold on any deposit changes. Ask them to:
- Require live, out-of-band verification (e.g., a phone call to your known number) for any future changes.
- Set a note or flag on your payroll profile about heightened verification.
- Confirm the date of your next payroll processing run so you can watch for tampering.
- Secure your payroll and employer accounts. Change your password for any payroll or benefits portal, and turn on strong multi-factor authentication (MFA) using an authenticator app or hardware key. Avoid SMS when possible.
- Contact your bank to add account-level safeguards. Ask the fraud team to:
- Place ACH debit alerts and large-transaction alerts on your account.
- Enable out-of-band verification for new external links or payment authorizations.
- Discuss whether a new account number is warranted if your account number and routing number were fully exposed, especially if you see suspicious activity.
- Freeze your credit at all three bureaus (Experian, Equifax, TransUnion). While direct-deposit fraud doesn’t require new credit, breaches often expose adjacent personal data. A freeze blocks most new credit accounts opened in your name without your permission and is free to place and lift.
- Update passwords and MFA on your primary email accounts. Your email controls password resets for payroll portals and banks. Use unique, strong passwords and MFA; consider a reputable password manager.
Protect Your Paychecks from Rerouting Scams
Paycheck diversion is the most common risk after direct-deposit details are exposed. Criminals impersonate you to request a change right before payroll runs. Reduce this risk with these steps:
- Set a “no-change without voice verification” rule. Ask HR to require a live phone call to your verified number for any change, even if a request appears to come from your work email.
- Use a known phone number. If HR calls, make sure they use the number already in your file—not a number added in a change request.
- Be cautious with company email and collaboration tools. Attackers may spoof your address or compromise your inbox to push a last-minute change.
- Confirm deposits after each payroll run. Check that your net pay hits your account on the expected date and time.
What If Your Bank Account Number Was Fully Exposed?
Account and routing numbers are sensitive, but by themselves they’re generally used for incoming deposits or authorized ACH debits. Criminals may still try to exploit them with social engineering or unauthorized pulls.
- Turn on ACH and transaction alerts. Immediate alerts let you spot and dispute unauthorized activity fast.
- Ask your bank about ACH blocks or debit filters. Some banks can restrict which parties can debit your account, especially useful for business accounts.
- Consider a new account number if activity looks suspicious. If you detect any unauthorized ACH or your bank advises it, open a new account and migrate legitimate deposits and bills methodically.
- Never share one account for both payroll and broad bill-pay if you’re cleaning up exposure. Keeping a “clean” account for income and a separate account for day-to-day expenses can limit fallout if credentials are misused.
Secure Portals and Emails That Control Deposits
Your online accounts are the control panel for pay and benefits. Hardening them can stop takeover attempts even if some data is exposed.
- Payroll portal: Change password, enable MFA, review recovery email/phone, and remove old devices or sessions.
- Employer SSO or HR portal: Update password and MFA; verify security questions; remove unused app connections.
- Primary email(s): Update password and MFA; review forwarding rules and filters that could hide fraud-warning emails.
- Tax account (IRS online services or state revenue portal): Enable MFA and verify bank info and mailing address are correct.
If a Deposit Was Already Diverted
If your paycheck or benefit payment didn’t arrive as expected, act the same day.
- Contact HR or payroll immediately. Ask whether a change request was received and when it was processed. Provide proof of identity and request reversal procedures.
- File internal fraud reports quickly. Many payroll processors can attempt to recall funds if notified in time.
- Report to your bank’s fraud department. Even though this is an incoming deposit issue, your bank can document the incident and assist with related risks.
- Create a written record. Keep dates, times, names, and case numbers from HR, payroll processors, and your bank. Documentation helps with reimbursement and law-enforcement reports if needed.
Special Situations: Government Benefits and Tax Refunds
Benefit and tax accounts can also be targeted for rerouting once criminals have partial banking or identity data.
- Social Security or VA benefits: Contact the agency directly using the official phone number on its website. Request a lock on deposit changes and confirm your current direct-deposit details.
- State unemployment: Log in to your portal, change passwords, enable MFA, and verify banking info. Many states can flag your account for extra verification on future changes.
- IRS and state tax accounts: Create or secure your online account, add MFA, and verify banking and mailing details. If you suspect attempted fraud, consider filing early and use extra verification steps where available.
Identity and Financial Monitoring After a Direct-Deposit Exposure
Even if no money is missing now, breaches can fuel later identity misuse. Ongoing monitoring helps you spot new problems early.
- Credit freeze: Keep it in place long term; lift temporarily when you truly need new credit.
- Bank and card alerts: Real-time alerts for large transactions, new payees, external transfers, and ACH debits are essential.
- Tax transcript and account checks: Periodically sign in to confirm no unauthorized changes to refund methods or address.
- Email breach checks and password hygiene: If the breach also exposed your email or password, rotate unique passwords everywhere that matters and ensure MFA is on.
How to Talk to Your Employer or Payroll Team
Use clear language that prompts protective action. Here’s a simple script:
“I was notified that my direct-deposit information was exposed in a data breach. Please place a hold on any direct-deposit changes to my account and require voice verification to my existing number for any future updates. My next payroll is scheduled for [date]; please confirm no changes are pending. I will also update my payroll portal password and MFA today.”
Request a written confirmation of these controls and a point of contact if issues arise.
When to Consider Replacing Your Bank Account
Replacing your account number is disruptive. Consider it if any of the following are true:
- You see an unauthorized ACH debit or suspicious external link attempts.
- Your bank recommends replacement based on the exposure and risk profile.
- Your payroll or benefit deposits have been diverted or targeted multiple times.
If you replace the account:
- Open the new account first and enable alerts and MFA where applicable.
- Move payroll deposits and essential bills deliberately; confirm each pay cycle hits the new account before closing the old one.
- Update linked services (pay apps, brokerages, tax portals) and remove the old account everywhere it’s stored.
Documentation and Recovery Checklist
Keep a concise paper trail and follow a routine during the first weeks after exposure:
- Save the breach notice and any timelines provided by the affected company.
- Record every call or message with HR, payroll, and your bank (date, time, contact, summary).
- Confirm deposit receipt on payday and the day after.
- Review bank transactions daily for two weeks, then weekly for two months.
- Revisit portal security monthly: ensure MFA is active and recovery info is correct.
Common Myths to Ignore
- “If no money is missing, I don’t need to do anything.” Rerouting attempts often happen right before payroll. Put protections in place now.
- “A routing and account number can’t hurt me.” While more limited than a full identity theft, these numbers enable social engineering and unauthorized debits.
- “Email MFA is enough.” Use an authenticator app or hardware key for stronger protection against SIM swaps and phishing.
Practical Prevention for the Future
- Use unique, strong passwords and an authenticator app for payroll, bank, tax, and email accounts.
- Designate a stable phone number for verification and keep HR updated.
- Beware of change-confirmation emails. If you receive one you didn’t initiate, call the organization using a known number immediately.
- Review payroll settings quarterly. Verify deposit accounts, contact details, and recovery options.
Related Reading
If you’re not seeing fraud but want a structured plan, read: What Should You Do After a Data Breach If You See No Fraud Yet?
If your email and password were also exposed, learn how to triage accounts: How Should You Prioritize Accounts After Your Email and Password Are Exposed?
Optional Next Step
After you’ve secured payroll and banking, consider ongoing credit and identity monitoring to catch new changes early. You can evaluate one option here: SmartCredit for privacy, credit monitoring, and identity protection.
Conclusion
When a breach exposes your direct-deposit instructions, time matters. Lock down payroll changes with your employer, harden the accounts that control deposits, set strong bank alerts, and monitor closely around payday. If anything looks off, escalate the same day with HR and your bank. With these steps, you can block rerouting scams, keep your income flowing to the right place, and reduce the chance of longer-term identity risks.
Good to Know
Payroll rerouting fraud often starts with a simple email or portal change request. Always confirm any direct-deposit change with a live person using a known phone number, not links or contacts provided in a message.