HR received a payroll account change request. How do you verify the employee?
A routine payroll request can redirect a salary to a scammer. Learn how to verify account changes safely and respond if the payment has already gone out.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 18 September 2026
- READING TIME
- 14 min read
- TOPIC
- Human Security
HR receives a short message: “Hi, please send my salary to this new account from the next payroll. I am away today, but I need this changed before the payroll run closes.” The signature, job title and writing style look familiar. The sender knows the HR specialist’s name, the pay date and even part of the internal process. The attachment resembles the company’s form.
It may be a genuine employee request. It may also be an attempt to redirect an entire salary to a scammer. Sometimes the criminal merely spoofs the sender address. In other cases, they control the employee’s real mailbox or payroll portal credentials. The message can then come from the correct account and appear inside an existing conversation. The email address alone does not establish who requested the change.
A resilient organization does not expect an HR specialist to identify every fraud attempt by instinct. It creates a simple process that sends every payroll-account change — genuine or fraudulent — through the same independent verification.
Why the request feels credible
Changing a payroll account is an ordinary life event. Employees move banks, close joint accounts, relocate or reorganize their finances. HR processes many such requests, often close to the payroll cutoff. The scammer exploits that routine.
They may first research the company, its team structure and the people responsible for HR. Professional networks, job adverts and email signatures can reveal those details. A compromised mailbox provides more: writing style, leave dates, the payroll timetable and old forms.
Unusual grammar or tone can therefore be useful warning signs, but their absence is not proof. A strong fraudulent message may contain no obvious errors. A genuine employee may write hurriedly from a phone. The process should authenticate the person and request, not grade the prose.
The core rule: verify through a different, previously known channel
Do not reply with “is this really you?” If the mailbox is compromised, the scammer will answer. Do not call a number supplied in the same message or new form. That remains a channel chosen by the sender.
Use contact information the organization already held before the request:
- a phone number previously stored in the HR system;
- an in-person conversation or company video call with someone you recognize;
- an approved employee portal that requires fresh authentication;
- contact through the employee’s manager when the employee cannot be reached directly.
During the conversation, do not read out the full new account and ask only for agreement. Ask the employee to explain the request and state the final digits themselves. That makes it harder for someone answering a diverted call to succeed with a simple “yes.”
No answer is not approval. It means the change waits. An urgent tone, business travel, illness or request for discretion must not disable the control designed to protect the employee’s pay.
A payroll procedure that works under pressure
1. Hold the change
Mark the request as pending. Do not copy the account into payroll merely so you “do not forget,” and do not place it first in a working spreadsheet. One premature update can later flow into the payment file.
2. Open the employee record independently
Reach the HR system through your own bookmark or known address, never through the message link. Compare the employee identifier, existing details and stored contact number. Treat the attachment as the content of a request, not identity evidence.
3. Confirm the person and the details
Use the known channel. Record when and how verification occurred and who performed it. In a small organization, this may be a brief conversation with the employee; in a larger one, approval in the portal or by another authorized person.
4. Apply a two-person check
One person enters the change and another compares the approved request with the system record. The check only works if the second person can see the source of verification, rather than a bare “checked” label. The point is not more signatures; it is preventing one mistake from becoming a payment.
5. Notify the employee through the old channel
After the update, send a notice to the previously stored email address or phone number stating when the change occurred and where to report an unauthorized update. Do not include the complete account number. This alert creates one final opportunity to respond before payday.
6. Review changes before releasing payroll
Before payments are approved, produce a short list of accounts changed since the previous cycle. The approver should see who verified each update and how. That is far more manageable than manually reviewing every employee.
Warning signs that require extra scrutiny
- the request arrives immediately before the payroll cutoff;
- the employee supposedly cannot talk and insists on email only;
- the sender asks HR to bypass the normal form or second approval;
- replies avoid the question when you suggest a phone call;
- the phone number or contact details change together with the bank account;
- the message comes from a personal mailbox, lookalike domain or chat app;
- the account belongs to a provider or country the employee has not used before;
- mailbox rules appear that hide HR confirmations after the change;
- one person asks to change the account, phone and recovery details at the same time.
No single point proves fraud. An employee may genuinely be abroad or unable to use their phone. A cluster of signs does mean the normal verification must not be shortened.
What not to do, even when the request looks normal
Do not treat a matching name and signature as authentication. Do not rely solely on the mail system labeling the message as internal. Do not request an identity-document photo by email — the document may be stolen, and the company would create another risk for the employee.
Do not make a “test payment” to the new account. Sending a small amount does not prove the account belongs to the right person. Screenshots from a banking app are not sufficient either; an image can be altered, and a genuine screenshot still does not authenticate the sender.
Do not explain the company’s detailed controls to the attacker. A neutral response is enough: “We verify payroll-data changes through our standard process.” The less an attacker knows about questions and exceptions, the harder it is to prepare the next attempt.
If the account changed but payroll has not gone out
Pause the payroll file or its approval. Restore the earlier details only after reviewing the change history and confirming with the employee. Preserve the message, attachments, modification time, account used to make the change and HR-system records. Do not delete the correspondence after recognizing the fraud.
Check whether similar requests arrived for other employees. If the message came from the genuine mailbox, the security team should end unfamiliar sessions, secure the account and inspect mail-forwarding rules. Tell the employee calmly that someone may have impersonated them and that the process stopped the change.
If the salary has already reached the wrong account
The first minutes matter. The payment owner should immediately call the organization’s bank on an official number, identify the fraudulent transfer and request an attempt to stop or recover it. Do not wait for a complete internal investigation before making that first report. Recovery is not guaranteed, but delay reduces the available options.
Inform the employee, management, legal team or incident owner in parallel. Establish a safe way to provide the pay owed; do not make the employee carry the burden of dealing with the company’s bank. Preserve the payment file, confirmations, correspondence and approval history. Report the loss to law enforcement according to the organization’s process.
After the incident, do not stop at warning the HR specialist. Ask why one message could change payroll data: was independent contact missing, did the second check fail, was there no employee alert, or were system permissions too broad? Repairing the process protects more people than assigning blame.
What employees can do
Employees can reduce the risk too. Submit payroll-account changes only through the established route. React immediately to a “your payroll details were updated” notice when you made no change. Do not approve an unexpected HR-portal sign-in or enter a password on a page opened from email.
If expected pay does not arrive, contact HR through an official number, not by replying in a suspicious thread. Ask on what date and to which bank the money was sent without requesting a full account number by email. Connecting the information from HR and the bank quickly provides the best chance to act.
What the sources confirm, and what Breachroad recommends
The FBI’s Internet Crime Complaint Center has described messages impersonating employees and asking HR to change direct-deposit accounts, and recommends verifying account changes through a second channel. A separate IC3 notice covers the variation in which criminals steal payroll-portal credentials and alter payment instructions themselves. Poland’s financial supervisor also explains the broader business email compromise pattern in which social engineering is used to induce business payments.
The two-person check, pre-payroll change report, old-channel notification and verification conversation are Breachroad recommendations. Organizations should adapt them to local employment law, their bank and HR platform. A related pattern appears in business email compromise and CEO fraud. HR and finance teams can rehearse these decisions in our employee cybersecurity training.

