Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Payroll Diversion Fraud Explained: How Criminals Redirect Staff Salaries

In short

Payroll diversion fraud is when a criminal impersonates one of your employees and asks payroll to send that person's salary to a new bank account — theirs. It usually arrives by email and relies on trust and time pressure. The fix is simple: verify every bank-detail change out-of-band, and protect email accounts with MFA.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

The scam in one sentence

A criminal pretends to be one of your employees and asks whoever runs your payroll to pay that person’s next salary into a new bank account. The account belongs to the criminal. The money leaves on payday, the real employee doesn’t get paid, and by the time anyone notices it has usually gone.

This is called payroll diversion fraud (sometimes “payroll redirect” or “salary diversion”). It’s a close cousin of business email compromise, and it works on businesses of every size — including small firms that assume they’re too small to bother with.

How the con actually plays out

It nearly always starts with an email. Payroll or the business owner receives a short, polite message that appears to come from a member of staff:

“Hi, I’ve switched banks. Could you please update my details so my next salary goes to the new account? Sort code and account number below. Thanks!”

Sometimes the email comes from the employee’s genuine mailbox, because the criminal has already stolen the password and logged in. Sometimes it’s a lookalike — the display name reads “Sarah Jones” but the actual address is a free webmail account, or a domain with one letter changed. Either way, the request seems ordinary. People do change banks.

The payroll person updates the record. On payday, the salary lands in the criminal’s account. The real employee chases their missing wages days later — and only then does anyone realise what happened.

Why it works so well

Payroll diversion succeeds because it doesn’t rely on clever technology. It relies on how normal offices behave.

  • It’s a routine request. Nobody expects a salary bank-change to be a scam. It’s admin, not an emergency.
  • It uses real names and real context. Criminals research your team on LinkedIn and your website. The email uses the right names, sometimes the right tone.
  • It arrives with just enough pressure. “Before the next payroll run, if possible” nudges people to act quickly rather than check.
  • There’s often no verification step. In many small firms, an email is treated as authorisation. That single gap is the whole vulnerability.

Crucially, no malware is involved. Your systems aren’t “hacked” in the way people imagine — a person is simply persuaded to move money. That’s why antivirus alone can’t stop it.

The one habit that stops it: verify out-of-band

The single most effective defence is a rule you can write on a sticky note:

Never change salary bank details based on an email alone. Always confirm the change by a separate, trusted channel first.

“Out-of-band” simply means using a different route from the one the request came in on. If the request arrives by email, you confirm it by phone. And you ring the number you already have on file for that employee — never a number written in the email itself, because a criminal will happily give you their own.

In practice:

  • Phone the employee on their known mobile, or speak to them in person.
  • Ask them to confirm the change out loud. A thirty-second call defeats the entire scam.
  • If you can’t reach them, the change waits. A genuine employee will not be upset that you checked before moving their wages.

Make this the rule for everyone, with no exceptions for senior staff or “urgent” requests. Fraud thrives on exceptions.

Lock down the email accounts themselves

Out-of-band verification catches the request. Good account security stops criminals reading your mail and impersonating your people in the first place.

  • Turn on multi-factor authentication (MFA) on every email account. MFA means a stolen password alone isn’t enough to log in — the criminal also needs a code from the real user’s phone. It’s the biggest single upgrade you can make, and it’s now a baseline requirement under Cyber Essentials. Our plain-English guide to multi-factor authentication explains how to set it up.
  • Use a password manager so every account has a strong, unique password. Reused passwords are how one leaked login becomes a mailbox takeover. A tool like Proton Pass generates and stores unique passwords so staff don’t have to remember them.
  • Train the team to spot phishing. Most account takeovers begin with a phishing email that harvests a password. Knowing how to spot a phishing email closes the door before the criminal gets in.

A quick checklist for finance and payroll

  • Any request to change salary bank details is verified by phone using a number already on file — every time.
  • The person requesting and the person approving a bank-detail change are never the same individual, where your team size allows.
  • Payroll staff know it’s completely acceptable to pause a payment to check. Speed is never worth more than the salary.
  • MFA is switched on for every mailbox, and staff use unique passwords.
  • New starters and payroll deputies are told the verification rule on day one, so cover doesn’t create a gap.

If you think you’ve been hit

Move quickly — recovery depends on hours, not days.

  1. Contact your bank immediately and ask them to attempt a recall of the payment.
  2. Report it to Action Fraud (or Police Scotland in Scotland).
  3. Check whether the email account was compromised — change the password, force everyone out of active sessions, and switch on MFA if it wasn’t already.
  4. Warn the rest of the team, because criminals often try the same trick on several staff at once.

The bottom line

Payroll diversion fraud isn’t sophisticated. It’s a confidence trick dressed up as routine admin, and it’s beaten by one boring, reliable habit: pick up the phone before you move the money. Add MFA on your email accounts and a password manager behind that, and you’ve closed the gap most criminals are counting on.

If you’d like help putting these controls in place — MFA, phishing training and a clear finance verification process — get in touch with DACROS. We help small businesses across Leeds and Yorkshire make security simple, and you can see the full range on our cyber-security page.

Frequently asked questions

Will our bank refund a diverted salary payment?

Not always. Because your own staff member authorised the payment (believing the request was genuine), banks often treat it as an authorised push payment rather than fraud on the account. UK reimbursement rules have improved, but recovery is never guaranteed — prevention is far more reliable than trying to claw money back afterwards.

How is this different from an employee simply changing their bank details?

It looks identical, which is the whole problem. A real employee occasionally does switch bank accounts. That is exactly why you need one fixed rule for everyone: any change to salary bank details is confirmed by voice or in person using a number you already hold, never a number or reply address supplied in the request itself.

The email came from our employee's real address — how?

Either the criminal has taken over that mailbox (often after a phishing email captured the password), or they have spoofed the display name so it merely looks like your employee. Both are common. That's why the email address alone should never be enough to authorise a change.

We're a tiny team — are we really a target?

Yes. Criminals send these requests in bulk and don't care how big you are; a five-person firm's payroll run is still worth stealing. Smaller businesses are often targeted precisely because they're less likely to have a formal verification step in place.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.