Home Articles Get your free assessmentComing soon

Payroll Diversion: The Email That Steals Someone’s Paycheck

Illustration: a kitchen table with a laptop showing a payroll change form

Most of the attacks in this series steal from the organization. This one steals from a person on your staff — and they usually don’t find out until payday, when the money simply isn’t there.

The email goes to whoever handles payroll. It appears to come from a staff member:

Hi Karen — I’ve switched banks. Could you update my direct deposit before Friday’s run? New details attached. Thanks!

That’s it. No urgency theatre, no drama. Just an administrative request of a kind that arrives legitimately several times a year.

Karen updates the record. On Friday, that staff member’s entire paycheck lands in an account controlled by a stranger, and the person who earned it opens their banking app to find nothing.

Why this one hurts differently

It’s worth naming the human dimension before the technical one, because it changes how you should respond.

When BEC takes $40,000 from the church, the organization absorbs a loss. When payroll diversion succeeds, an individual — often someone on a modest church salary — misses rent. And there’s frequently no clean answer about who makes them whole. The employer may not be legally obliged to pay twice. The bank may not recover it. The person did nothing wrong at all; they were simply impersonated.

That’s why this deserves its own attention rather than being folded into general invoice fraud. The victim is a colleague, and the fallout is personal.

The two ways in

The impersonation route. The attacker sends from an outside address with the staff member’s name as the display name — the friendly label your mail app shows instead of the actual address. It’s free text; anyone can set it to anything. On a phone, where the real address is hidden entirely, the message looks exactly like it came from your colleague.

The account takeover route. More dangerous and, according to FBI advisories, the common pattern. The staff member is phished first — they receive a message that looks like it’s from the payroll provider or the IT helpdesk, follow a link to a convincing but counterfeit login page, and type in their credentials. Now the attacker has a genuine account, and the request to change direct deposit comes from the real address, in a real thread, from a real person’s mailbox.

In the takeover version, attackers commonly do something that makes this much worse: they disable change notifications. Most payroll systems email the employee when their banking details are updated. The attacker turns that off first, which is why the theft goes unnoticed until payday rather than within the hour.

They also frequently add a mail rule that quietly files any message containing “payroll,” “direct deposit,” or “deposit change” into an unread folder, so the employee never sees the confirmation even if one slips through.

The FBI has warned about this pattern since 2018, noting that attackers use stolen credentials to access the employer’s HR system, replace the employee’s banking information, and then suppress the alerts. The Bureau’s guidance to employers is direct: require separate credentials for payroll systems, use two-factor authentication, and establish protocols requiring extra approval for banking change requests.

What makes a church or nonprofit vulnerable

Payroll is often one person’s job, done in a hurry. There’s no HR department. The office administrator handles payroll alongside facilities, bulletins, and the phone. A one-line request that takes ninety seconds to action gets actioned.

Direct deposit changes are genuinely routine. People do switch banks. Requests like this arrive legitimately, which means there’s no natural suspicion attached to the category.

Staff email addresses are public. Your staff page lists them. An attacker can determine who does payroll and who to impersonate without any access at all.

The window is predictable. Payroll runs on a schedule. An attacker who knows you pay on the 15th and the last day of the month knows exactly when to send, and exactly how long they have before anyone notices.

The control that stops it

One rule, and it mirrors the one for vendor payments:

No banking change is ever actioned from a written request alone. The person is called back on the number already in their personnel file, and asked to confirm.

The details matter.

Called back — you initiate the call. Don’t accept a number supplied in the request, and don’t accept a call from someone claiming to be the employee. The direction of the call is the control.

The number already on file — from the personnel record, not the message signature. If your only number for them is one they gave you recently by email, that’s worth fixing.

Confirm the specifics — read the last four digits of the new account number aloud and ask them to confirm. Don’t ask “did you request a change?” A yes-or-no question invites a yes from someone who isn’t listening carefully.

Two additions worth making. Impose a deliberate delay — banking changes take effect on the next payroll run, not this one. Attackers depend on a change landing before the next payday; a one-cycle lag removes the whole business model. And notify the employee through a second channel whenever their details change — a text or a call, not just an email, because the email may be sitting in a folder the attacker created.

Hardening the systems

Multi-factor authentication on email and the payroll portal, separately. This is the extra code or tap after the password. It’s the single control that defeats the account-takeover route, and it’s free on Microsoft 365 and Google Workspace. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. Make sure your payroll provider’s portal has it enabled too — it’s often a separate setting that nobody has turned on.

Use different credentials for payroll. If your payroll login is the same password as your email, one phishing success gives away both. This is exactly the FBI’s recommendation.

Turn change notifications back on, and check they’re on. Then verify quarterly that they haven’t been switched off. In the payroll system, confirm that alerts go to an address the employee controls and, ideally, to a second person in the office.

Audit mail rules. Once a quarter, in each staff mailbox, look at the forwarding rules and filters. A rule nobody remembers creating — especially one that files or forwards messages containing payroll keywords — is a strong signal that the account has been compromised. This is the most commonly overlooked step after a password reset.

Teach the staff member’s side too

The control above protects the organization’s process. Your team also needs to recognize the phishing that precedes the takeover.

Tell them plainly: you will never receive a legitimate email asking you to log in to view a pay stub, confirm your direct deposit, or re-verify your payroll account. If a message like that arrives, don’t use the link. Open a browser and go to the payroll site the way you normally do, or call the office.

That single habit — never sign in from a link in a message — defeats credential phishing in every form, not just this one.

If it already happened

Move immediately; this is recoverable more often than people expect, but only quickly.

Call the bank that received the money and report the deposit as fraudulent. If the payroll run has processed but the funds haven’t been withdrawn, they can sometimes be frozen.

Call your own bank and your payroll provider and ask about a reversal. Some ACH transfers can be recalled within a narrow window.

Report it to the FBI at ic3.gov, and use the words payroll diversion and business email compromise. The Bureau’s Recovery Asset Team can trigger a process to freeze funds in transit — in 2025 it ran 3,574 domestic cases and froze $507,042,623. It works dramatically better inside the first day or two.

Assume the mailbox is compromised until proven otherwise. Change the password from a different device, revoke all active sessions (“sign out everywhere”), re-enable MFA, and check for mail rules the attacker added.

Then take care of the person. Decide quickly whether the organization will cover the missed pay while recovery is attempted. Whatever you decide, decide it fast and say it plainly — a staff member who has lost a paycheck through no fault of their own should not spend a week wondering.

What to do this week

Write down one sentence and give it to whoever runs payroll: Banking changes are confirmed by calling the employee on the number in their personnel file, and take effect on the following pay run.

Then check two settings — that change notifications are turned on in your payroll system, and that multi-factor authentication is enabled on the payroll portal as well as on email.

Half an hour, and this attack stops working on you.

MissionDefend’s free assessment walks through exactly these kinds of gaps in plain English — how you handle email, donations, member data, and accounts — and gives you a ranked list of what to fix first.

No spam and no sales calls — just one email when it’s live.


MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

Sources: FBI, Building a Digital Defense Against Payroll Phishing Scams; FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.

Found this useful? Pass it on.

Facebook X LinkedIn Email