How to train HR teams to stop payroll diversion scam emails

Payroll diversion scam training for HR teams in 2026: verify every bank detail change by phone, drill the pay-run scenario and stop salary redirect fraud.

A payroll diversion scam targets the one team that can redirect a salary with a few keystrokes: HR and payroll. The email appears to come from a genuine employee asking to update their bank account for next pay run, and the money lands in a criminal's account until someone notices, weeks later. This 2026 guide trains HR and payroll teams to verify every bank change through a known channel before it reaches the pay run.

TL;DR

Why this matters

The FBI has repeatedly warned that criminals email HR and payroll staff impersonating employees to redirect direct deposit payments to accounts the criminals control, and the tactic has not faded: a successful diversion means an employee works for weeks without real pay while the stolen wages are quickly moved on. In Australia the same pattern appears in Scamwatch reporting as payment redirection, where the guide to spotting and avoiding scams describes criminals sending false invoices or account change requests that look like normal business.

The scam works because the request is ordinary. Employees change banks for real reasons all the time, so a request that arrives from what looks like the employee's own address, with the right names and tone, gets processed as a Tuesday task rather than a fraud attempt. The consequences fall on both sides: the employee misses pay, and the employer faces a costly recovery and an awkward conversation about why nobody called to check.

Start with security awareness training so verification is a process rule, not a judgement call made under deadline.

What you'll need

Run the drill as a no-fault exercise. The goal is a verification habit that survives a busy pay run.

Step 1: Name the attack

Show the class of email rather than one message: a request to update direct deposit details, sent from an address that looks like the employee's, often with a plausible reason such as a new bank or a phone upgrade. Some versions follow up by phone using a cloned voice, which how to train staff to recognise fake AI voice cloning scams drills separately.

Expected outcome: Staff can describe the pattern in one sentence. Common mistake: Treating a plausible reason as verification.

Step 2: State the rule without exceptions

No bank detail change is ever processed on the strength of an email alone. Every change is confirmed by calling the employee on the number already stored in the HR system, or verified face to face. If the employee cannot be reached, the change waits until the next pay run.

The rule exists precisely for the days when the pay run is due and the inbox is full. A process that flexes under pressure is not a process.

Expected outcome: Staff can state the rule and the exception count, which is zero. Common mistake: Making an exception for senior staff or long-serving employees.

Step 3: Teach identity checks that survive spoofing

A callback to the number on file defeats a spoofed email completely, because the criminal controls the email but not the employee's phone. Add one knowledge check the criminal cannot answer from a mailbox: a detail from the HR record, such as start date or last pay amount, asked conversationally.

Expected outcome: Staff perform the callback without being prompted by a checklist. Common mistake: Calling the number quoted in the email, which reaches the scammer.

Step 4: Rehearse the scenario

Run a two-minute drill. The learner receives an email from an employee changing banks, pay run tomorrow, mentions a phone issue so please don't call the mobile. The learner refuses the no-call trap, calls the HR-system number, discovers the employee sent no such request, and reports the email.

Phishing simulations carry the same scenario safely, and varying the pretext between banks, phone loss and relocation keeps the drill honest.

Expected outcome: The learner completes callback-then-report without processing the change. Common mistake: Making the simulation so easy that the verification step never feels costly.

Step 5: Watch for the follow-up pattern

Real campaigns rarely stop at one email. A failed diversion attempt is often followed by a second request from a different employee, a phone call pressing urgency, or an invoice-themed email to finance in the same week. Brief the team that one attempt means more are likely, and that finance teams face the same pressure through supplier bank change requests.

Expected outcome: Staff connect a failed attempt to elevated risk for the whole pay cycle. Common mistake: Treating the first blocked attempt as the end of the incident.

Step 6: Capture the report

A useful report includes the sender address, the claimed employee, the account change requested and any follow-up contact. If a change was already processed, payroll contacts the bank immediately; recovery odds drop with every hour.

Make reporting one click from the inbox. Cyber Aware phishing simulations include a report button so the same reflex carries into real incidents.

Expected outcome: Reports reach security within minutes, with the details above. Common mistake: Fixing the record quietly and telling nobody.

Step 7: Target the follow-up

Payroll diversion attempts cluster around pay runs and public holidays, when genuine changes are common and staffing is thin. Use human risk reporting to check which teams verified and which rushed, then re-brief before the next cycle rather than after an incident.

Expected outcome: Briefing lands before the next pay run, not after the next fraud. Common mistake: One annual reminder in a low-risk month.

Troubleshooting

An employee is genuinely unreachable on pay day

The change waits. Processing an unverified change to be helpful is exactly the failure the rule prevents; a delayed pay run for one employee beats a stolen one.

The request came from the employee's real address

Treat the mailbox as compromised and verify by phone regardless. A real mailbox that requests a change is a more serious signal, not a safer one.

A change was already processed before the scam was caught

Contact the bank immediately, report through the agreed route and notify the affected employee plainly. Respond without blame so future reports stay honest.

Payroll staff feel the verification step slows them down

Measure the cost honestly: one callback per change, a few minutes each. Compare it with a single successful diversion and the trade is never close.

Tools and resources

What to do next

Run the payroll diversion scenario once in the next 30 days, before the next pay run, and measure how many changes get verified by phone without prompting. A complete verification rate is the 2026 benchmark; use the result to set the next training reminder.

FAQ

What is a payroll diversion scam?

It is a fraud in which criminals impersonate an employee by email and ask HR or payroll to redirect their salary to an account the criminals control.

How do we verify a bank detail change safely?

Call the employee on the number stored in the HR system, not any number in the email, and confirm the change plus one detail from the HR record.

What if the email really is from the employee's address?

Verify by phone anyway. A real mailbox making the request suggests the account is compromised, which is a more serious incident, not a reason to skip the check.

Who should own the verification step?

Payroll, with HR as backup. The step must sit with whoever touches the pay run, and never with the requester.

What should we do if wages were already diverted?

Contact the bank immediately, report the incident internally and to Scamwatch, and tell the affected employee. Fast reporting gives the best chance of freezing the funds.

How often should payroll diversion training run?

Before every major pay cycle change and at least twice a year, timed ahead of pay runs and public holidays when attempts peak.

One last thing

The scam succeeds only when the verification step feels optional. A rule with no exceptions, rehearsed until the callback is automatic, closes the gap the email depends on.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.