← All terms

Payroll Diversion

Payroll diversion is a business email compromise variant in which an attacker impersonates an employee to redirect their salary to a bank account the attacker controls.

Payroll diversion (also called direct-deposit fraud or payroll redirect fraud) is a form of business email compromise in which an attacker, posing as an employee, asks HR or payroll to change the employee's direct-deposit details to a new bank account. The next salary run pays the attacker instead of the employee, and the fraud is usually discovered only when the real employee asks why they were not paid. Unlike invoice fraud, which targets accounts payable with a supplier pretext, payroll diversion targets the HR and payroll function with an employee pretext — and because the amounts are individual salaries rather than large invoices, requests often slip beneath the thresholds that trigger extra scrutiny.

How it works

The attacker starts with reconnaissance: names, roles and email formats harvested from LinkedIn and the company website, sometimes supplemented by a self-service HR portal login obtained through phishing. They then either spoof or register a look-alike address, or in the stronger variant take over the employee's real mailbox through account takeover, and send a polite, low-urgency request to payroll: "I've switched banks — can you update my direct deposit before the next pay run?" A form may be attached, often a real copy of the company's own template. Because the request is routine, arrives from a plausible address and asks for nothing unusual, it is frequently processed without a callback. In the APWG Phishing Activity Trends Report for Q1 2026, payroll diversion accounted for about 11% of the BEC cash-out methods observed, alongside gift cards (48%) and wire transfers (19%).

How to defend

The control is procedural rather than technical: no bank-detail change is actioned on the basis of an email alone. Payroll should verify every change by calling the employee on the phone number already on file — never a number supplied in the request — or by requiring the change to be made by the employee inside an authenticated self-service portal protected by phishing-resistant MFA, with a notification sent to the employee's existing contact details. Add a short hold before the first payment to any newly added account, and alert on portal bank-detail changes that follow a recent password reset or login from a new location. Train HR and payroll staff specifically on this pretext as part of role-based security awareness training, and include a payroll-change scenario in phishing simulations for those teams — the broader playbook is in our guide to business email compromise defense. Employees themselves should be told at onboarding, as our new hire security onboarding guide recommends, that the company will never ask for banking details by email or text.

Related terms

Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.Invoice FraudInvoice fraud tricks a company into paying a fake or altered invoice, typically by impersonating a real supplier and changing the bank account details.Vendor Email Compromise (VEC)Vendor email compromise hijacks a supplier's real email account or thread to redirect customer payments — BEC's hardest-to-spot variant.Account Takeover (ATO)Account takeover is an attack in which a criminal gains control of a legitimate user account and operates it for fraud, theft, or further attacks.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo