The essentials
- The request came from a spoofed lookalike address or the employee's genuinely compromised mailbox — determine which, because the second means a live intrusion.
- Bank recall is a race measured in hours, exactly like wire fraud: call the moment the diversion is discovered.
- Search for other pending or recent detail changes now — these campaigns hit many employees at once.
- Verify every change with the employee by phone or in person, never by replying to the requesting email.
- The lasting fix is procedural: out-of-band verification for every banking change, no exceptions for urgency.
Payroll diversion is BEC's HR-department cousin: a polite email "from" an employee asking to update their direct deposit before the next run. The address is one letter off, or the mailbox is genuinely compromised — either way, payday sends their salary to a mule account.
It is usually discovered when the real employee asks where their pay went. From that moment, run it like wire fraud.
Do this now
- Start the bank recall. Your bank's fraud line, immediately: the payment reference, the receiving account, a recall request, and case numbers. Hours matter.
- Sweep for siblings. Audit every bank-detail change in the payroll system from recent weeks, and freeze pending ones until verified. One diversion found usually means several attempted.
- Verify with humans. Phone or face-to-face with each affected employee, on numbers from the HR system — not from the emails.
- Determine spoof versus takeover. Compare the requesting address character by character; check the real mailbox's rules, sessions, and sign-ins. A genuine compromise triggers the full mailbox-takeover response.
- Make the employee whole. Decide quickly how the missed salary is handled — policy or insurance question, but the employee should not be left waiting on the recall.
- Install the gate. From today: no banking change without out-of-band verification, regardless of how routine or urgent the request looks. Report the fraud to law enforcement as with any BEC.
What not to do
- Do not reply to the requesting email to "double-check" — the attacker answers.
- Do not blame the HR clerk who processed a request that looked exactly like hundreds of legitimate ones.
- Do not treat it as a one-off without sweeping for the rest of the campaign.
- Do not delete the request emails; headers prove the routing.
- Do not leave the verification gap open while "looking into process changes".
Preserve the evidence
Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:
- The change-request emails with full headers.
- Payroll-system audit logs of detail changes.
- Bank case numbers and the recall timeline.
- The spoof-versus-takeover determination and its basis.
Keep a clear head
The HR person who processed the change is having the worst week of their working year. Say clearly that the process failed, not the person — attackers pick payroll precisely because the request is routine and the pressure to be helpful is high. Blame teaches the next victim to hide the next one.
Questions victims ask
Who bears the loss — us or the employee?
The employee performed their work; as a rule the employer makes payroll whole while pursuing recall and insurance. Leaving the employee unpaid while banks argue is both legally risky and corrosive — decide fast and generously.
How do we tell a spoofed address from a compromised mailbox?
The spoof shows a lookalike domain or a reply-to mismatch in the headers. The takeover shows the genuine address plus artifacts in the mailbox itself — odd sign-ins, inbox rules, sent items the employee didn't write. The second is a bigger incident.
What does the permanent fix actually look like?
A standing rule with no urgency exception: banking changes require verification through a second channel (phone on file, HR portal with MFA, or in person). Attackers test workflows, not firewalls — the gate is the fix.