Scammers have learned that the fastest way to steal from you is to reroute your paycheck. One growing tactic is to send convincing messages that reference your real employer, HR software, or payroll portal. The message may look like it came from your HR team or a well-known platform, request a “required” payroll update, and push you to click a link or share sensitive information. This guide explains the red flags, safe verification steps, and the actions to take if you already interacted with a suspicious payroll-change request.
Why These Scams Work Now
Modern HR systems use recognizable brand names and routine emails (benefits elections, tax forms, direct deposit updates). Criminals mirror this rhythm and vocabulary. If your work email, job title, and employer are exposed on social media, data broker sites, or past breaches, a phony message can sound legitimate because it cites true details.
- Familiar brands: Messages cite real platforms like Workday, ADP, UKG, or SAP SuccessFactors to borrow trust.
- Real company details: Attackers scrape LinkedIn, company websites, and data broker listings to personalize messages with your employer’s name and even your manager’s title.
- Urgent pretext: They claim “payroll verification required,” “banking info mismatch,” or “action needed to avoid delayed pay.”
- Convenience pressure: The message includes a one-click link to “fix” the issue before your next payday.
Common Phishing Formats You Might See
- Email from “HR” or “Payroll”: A request to “confirm direct deposit” or “update bank routing” with a link to a fake portal.
- Text message (SMS) with your employer’s name: A shortened link claiming you must “complete verification today.”
- Messaging app note (Teams, Slack, WhatsApp): A “manager” posts a link to a “new payroll tool” for immediate sign-off.
- Phone call (voice phishing): A caller references your real HR system and asks you to read out your bank numbers “to fix a deposit error.”
- Lookalike login pages: The fake site copies your real portal’s design but sends your username and password straight to the attacker.
Red Flags That a Payroll-Change Request Is Fake
- Unusual sender address or domain: The email might use lookalikes (e.g., “adp-payrol.com” instead of “adp.com”) or a free mailbox.
- Links don’t match the real portal: Hover over links or press-and-hold on mobile to preview. If the URL doesn’t exactly match your known HR domain, stop.
- Unexpected urgency or threats: “Update in 2 hours to avoid a pay delay.” Real HR rarely uses threats or tight countdowns.
- Requests for sensitive info over email/text: Legitimate teams do not ask for full bank account numbers, full Social Security numbers, or one-time passcodes via message.
- Generic greeting or odd tone: “Dear Employee” or language that feels off for your company’s normal communication style.
- Outside your normal workflow: If your company always uses single sign-on or a bookmarked portal, a link that bypasses those steps is suspicious.
- File attachments you didn’t expect: “Payroll update form.xlsm” or “doc.html” can be malware or credential traps.
Quick, Safe Verification Steps
If you receive any payroll-change request, verify before you click, reply, or share information:
- Use your known path: Ignore any link in the message. Instead, open your usual bookmarked HR portal or go through your company’s intranet/SSO. If a real action is required, you’ll see it there.
- Confirm with HR directly: Call your HR or payroll team using a phone number from your company directory, not the number in the message. Ask if they sent it.
- Check official channels: Look for a parallel notice in your company’s HR system, Teams/Slack announcements from verified HR accounts, or email from a known internal distribution list.
- Inspect the sender and links: Compare the domain, display name, and reply-to address with past legitimate HR emails. Hover to preview every link for mismatched domains or odd parameters.
- Pause for timing: Real payroll cutoffs are usually on predictable schedules. Sudden “midnight” or weekend changes are unusual.
How Attackers Learn Your Employer and HR Portal
Phishers often combine multiple data sources to sound authentic:
- Public profiles: LinkedIn, personal websites, and conference bios reveal employer, title, and sometimes tools you use.
- Data brokers: People-search sites may list your employer and contact methods. Removing or limiting this data reduces targeting precision.
- Third-party breaches: If a vendor you used leaked your email or phone, attackers may tie it to your employer information via social media or old resumes.
- Email address patterns: Many companies use predictable formats (first.last@company.com), making spoofing easier.
Protective Settings You Can Turn On Today
- Enable MFA for HR and payroll accounts: Use app-based authentication or security keys. This helps block unauthorized logins even if your password is stolen.
- Use unique passwords: A password manager makes it easy to create and store different strong passwords for HR, benefits, and email.
- Bookmark your real HR portal: Always sign in from your bookmark or the company intranet, not from links in messages.
- Set bank account alerts: Turn on alerts for deposits, withdrawals, and changes to external transfers. You’ll detect redirected pay faster.
- Keep personal info lean online: Reduce exposed employer details on social media and opt out of data broker listings to limit targeted phishing.
What to Do If You Clicked the Link or Entered Info
Act quickly—time is critical to stop paycheck redirection or broader identity misuse.
- Disconnect and preserve: Close the tab, disconnect from public Wi‑Fi, and take screenshots of the message and site for your employer’s security team.
- Change passwords immediately: From a trusted device, reset your HR, email, and any account that reuses that password. Turn on MFA if not already.
- Notify HR/payroll and IT security: Ask them to freeze or review pending payroll changes and monitor your account for unauthorized edits.
- Contact your bank: If you shared banking info, notify your bank to watch for unusual activity and consider changing the account or routing arrangements.
- Check your credit and identity signals: Watch for new accounts, address changes, and other fraud indicators in the days and weeks after the incident.
- Run security scans: If you downloaded files or enabled browser extensions from the message, scan your device and remove anything suspicious.
How Employers and HR Teams Typically Handle Real Changes
Understanding normal process helps you spot fakes instantly.
- Portal-based updates: Legitimate changes are usually initiated only after you log in to the official HR portal. Email links are uncommon or limited to notifications that do not request credentials.
- Multi-step verification: Many companies require secondary verification (MFA or a secondary email/SMS) before bank details are changed.
- No rush threats: Real payroll won’t threaten to withhold pay within hours. Deadlines are communicated with reasonable lead time.
- Consistent branding and domains: Messages come from official domains and match prior communications and formatting.
Examples: Real vs. Phony Language
- Phony: “URGENT: Banking mismatch detected. Click here now to avoid pay disruption. Provide SSN and full bank info.”
- Legit (typical): “A change has been requested to your direct deposit. To review, sign in at your normal HR portal. If you did not request this, contact HR at the number in the company directory.”
- Phony: “New payroll vendor onboarding today—update credentials via the link by 3 PM.”
- Legit (typical): “We’re moving to a new payroll provider next month. You’ll receive multiple notices and can access the new portal from our intranet when available.”
Reduce Your Exposure to Targeted Payroll Phishing
When less of your personal and employment information is available online, fewer messages can convincingly impersonate your HR team.
- Audit your public footprint: Search for your name + employer and remove unnecessary mentions from profiles and posts.
- Opt out of people-search sites: Many brokers let you remove your profile. This reduces attacker context like employer, location, and phone.
- Use minimal work details on personal accounts: Consider listing industry instead of exact employer on public profiles.
- Segment your email addresses: Keep a unique address for HR/benefits that you don’t share widely, making spear-phishing harder.
Monitor for Signs of Financial or Identity Misuse
Payroll fraud attempts often correlate with broader identity risks. Proactive monitoring helps you spot and respond to trouble fast.
- Review pay statements: Confirm deposit amounts, bank account numbers (masked), and any address or tax withholding changes.
- Check credit activity: Look for new accounts or inquiries you don’t recognize. Early detection reduces the damage window.
- Watch for mail changes: Unexpected mail holds, change-of-address confirmations, or benefit re-enrollment notices can signal tampering.
For ongoing visibility into unusual financial and identity activity, consider a credit and identity monitoring solution that alerts you to new accounts, inquiries, and suspicious changes. A practical option is available here: SmartCredit for privacy, credit monitoring, and identity protection.
Report the Attempt and Help Others
- Inside your company: Forward the message to your security team or phishing mailbox. This helps them warn others and block lookalike domains.
- Email providers: Mark phishing emails as spam/phishing to improve filtering for everyone.
- Regulators (when appropriate): In the United States, you can report phishing to the FTC or local authorities. Your HR team may advise on specific steps.
Checklist: Before You Change Any Payroll Information
- Did the request arrive through your normal HR portal or was it a message with a link?
- Does the link domain exactly match your known HR site?
- Can HR confirm the request over a phone number you looked up yourself?
- Is there any unusual urgency or threat?
- Have you verified via your bookmarked portal or SSO that an action is actually pending?
- Do you have MFA enabled on your HR and email accounts?
If You’re an HR or Payroll Admin
Administrators can reduce risk with layered controls and clear communication:
- Require MFA and change approvals: Implement multi-approver workflows for direct deposit edits and vendor changes.
- Use change alerts: Send independent notifications (email and SMS) when bank details change, with instructions to verify via the portal.
- Standardize communication templates: Publish official domains and sample emails so employees know what real looks like.
- Train regularly with examples: Share recent phishing attempts targeting your organization and debrief what gave them away.
- Monitor lookalike domains: Register or watch for domains similar to your brand and request takedowns promptly.
Conclusion
Phony payroll-change requests can look and sound legitimate because they reference your real employer or HR portal. The strongest defense is simple: never follow a link in a payroll message. Instead, verify through your known, bookmarked portal or a phone call to HR using a number you trust. Enable MFA, use unique passwords, reduce your public employment footprint, and set alerts with your bank. If you slip, act fast—reset credentials, alert HR and your bank, and monitor for identity or credit changes. With steady habits and quick verification, you can keep your paycheck—and your personal information—out of a fraudster’s hands.
Good to Know
Legitimate payroll changes rarely require you to act immediately via a link in a message. If there’s real urgency, HR can confirm by calling you back at a known company number or by having you sign in through your normal bookmarked portal—never through a link in the message.