Payroll Diversion Fraud: When the 'New Bank Details' Email Is a Thief
It is Friday afternoon. The finance team is wrapping up payroll. An email arrives in everyone's inbox from an employee saying their bank account has changed and asking for details to be updated for next pay cycle.
The subject line reads something like "Urgent: Updated banking details" or "New account information". It looks legitimate because it comes from the person it claims to be from -- or at least, a very convincing version of them.
Within minutes, the bank details are changed in your system. The next pay run goes out. And forty percent of those funds disappear into accounts owned by criminals before anyone notices anything is wrong.
This is payroll diversion fraud and it costs Australian businesses millions every year. More importantly, it targets the people you trust most -- your own staff.
How Payroll Diversion Actually Works
The attack follows a predictable pattern that any business can protect against once they understand it:
Step 1 -- The Setup
Criminals spend time researching your company. They follow your social media accounts, monitor job postings to identify new hires or recent promotions and may even send phishing emails designed to compromise staff email accounts.
Sometimes they use publicly available information from LinkedIn profiles, company directories or professional networking sites to learn who works where and in what role.
Step 2 -- The Contact
The criminal makes contact through one of several channels:
- Compromised employee account -- An attacker breaches a real staff email account and sends the message from inside your trusted network
- Spoofed address -- They create an email that looks identical to a real employee's address, often by changing one character or using similar-looking domain names
- Social engineering call -- They phone HR or finance claiming to be the employee and say they cannot access their normal email
Step 3 -- The Urgency
The message creates pressure. It might reference an upcoming pay cycle, a personal emergency that requires quick action or simply state that the change needs to happen before the next payroll run.
Urgency bypasses careful thinking. When someone feels they need to act fast, they are less likely to follow verification procedures.
Step 4 -- The Payment
Once bank details are updated in your system, the next pay cycle routes funds to the criminal's account instead of the employee's real account. By the time you discover the fraud, the money has been moved through multiple accounts and recovery becomes extremely difficult.
Why This Works Against Small Businesses
Payroll diversion succeeds because it exploits the structure of small business operations:
- Limited verification layers -- Many SMEs have one or two people handling payroll without mandatory secondary approval for bank detail changes
- Trust-based culture -- Small teams rely heavily on trust and often skip formal verification steps that larger corporations would never bypass
- Shared email addresses -- Some businesses use generic addresses like admin@ or accounts@ which makes it harder to verify who actually sent a message
- Inconsistent processes -- Without documented procedures for handling banking changes, staff make ad hoc decisions based on whatever feels urgent
The criminal knows this. They study your business structure and target the weakest verification point they can find.
The Real Cost Beyond the Money
When payroll diversion hits a small business, the financial loss is only part of the damage:
- Employee distress -- Staff discover their money was stolen through no fault of their own. This creates anxiety, anger and erodes trust in the employer's ability to protect them
- Operational disruption -- Investigating fraud, contacting banks, filing police reports and updating systems diverts resources from normal business operations for weeks or months
- Reputational risk -- If client data was also compromised during the attack, customer confidence takes a hit that can be difficult to recover from
- Regulatory exposure -- Depending on your industry, you may have reporting obligations if personal information was involved in the breach
What Actually Stops Payroll Diversion
There is no single solution. You need layers of defence that make it impossible for fraudsters to succeed even if they bypass one control:
Technical Controls
Email Authentication (DMARC, DKIM, SPF)
These DNS records verify that incoming emails genuinely come from the domains they claim to represent. Without proper DMARC configuration, attackers can easily spoof employee addresses and your staff will have no technical indication that something is wrong.
Configuring these correctly means spoofed emails get flagged as spam or rejected before they reach inboxes. Staff receive clear visual indicators when an email appears to come from a colleague but fails authentication checks.
Multi-Factor Authentication (MFA)
If criminals compromise a real employee account, MFA prevents them from logging in and sending messages that appear authentic. They get blocked at the login stage before they can position themselves inside your trusted network.
Email Filtering and Impersonation Protection
Microsoft's built-in impersonation protection features detect when someone is masquerading as your executives or finance team members. Combined with Defender for Office 365 Safe Links, incoming messages that appear to come from staff but fail security checks get quarantined automatically.
Process Controls
Verify Before You Update Banking Details
This single rule stops more payroll fraud than any technology:
- Any request to change bank details must be verified through an independent channel
- Use a known phone number -- not one provided in the suspicious email or message
- Confirm verbally with the employee directly, ideally by calling their mobile on file
- Document every verification step taken and who authorised the change
Segregation of Duties
The person updating banking details should not be the same person authorising payments. Two sets of eyes on every transaction make it significantly harder for fraud to succeed.
Where possible:
- HR or payroll initiates bank detail changes
- Finance verifies through independent contact
- A manager approves the change before it takes effect
- The employee confirms receipt once the next payment arrives
Regular Employee Communication
Keep staff informed about this threat:
- Explain what payroll diversion looks like with real examples
- Clarify the verification process so everyone knows what to do
- Encourage reporting of suspicious requests without fear of blame
- Remind teams regularly -- especially before major pay cycles
How Secure365 Protects Against Payroll Diversion
Our managed service is specifically designed to close the gaps that leave SMEs exposed:
- Email authentication setup and monitoring -- We configure DMARC, DKIM and SPF correctly so attackers cannot spoof your staff addresses with confidence
- MFA enforcement across all accounts -- Including shared mailboxes and service accounts where it is often forgotten
- Impersonation protection tuning -- We set up Microsoft's built-in protections to flag messages targeting finance teams or executives before they land in inboxes
- Monthly security reporting -- You get clear visibility into your posture with recommendations tracked until completion
- Staff training support -- We help you develop communication materials that explain these threats in plain English
The goal is to make payroll diversion attacks fail at multiple points along the chain, so even if one layer is bypassed there are still safeguards in place.
Your Immediate Action Checklist
If you have not reviewed your payroll fraud protections this year, start here:
1. Check your email authentication records -- Run a free DMARC report and see what percentage of incoming mail fails verification checks 2. Audit MFA coverage -- Every account including shared mailboxes? Including staff who work remotely or use mobile devices? 3. Review your payroll change process -- Who updates bank details? Who verifies the change? Is there a paper trail? 4. Talk to your finance team -- Ask them how they would react if an email arrived today claiming urgent banking changes from a senior staff member 5. Test the system -- Send a test phishing email to see what percentage of staff click through or respond to requests for sensitive information
The Bottom Line
Payroll diversion fraud works because it exploits trust, urgency and simplified processes. It targets the people you employ and the systems you rely on to keep your business running smoothly.
The defences are well understood but require deliberate configuration and ongoing monitoring. They also need a culture where no single message overrides established verification procedures -- even when that message comes from someone everyone trusts.
That is what Secure365 exists to deliver so your team can focus on doing their jobs instead of worrying about whether that email requesting banking changes is real or fake.
If you want to know how payroll diversion could affect your specific setup and what gaps we would close first, reach out for a no-obligation review of your email security posture and payroll processes.
--- Article ID: JG-BLOG-2026-0726-01 | Category: Fraud / Business Email Compromise | Keyword Focus: Payroll Diversion | Secure365 Angle: Layers MFA, email authentication hardening and impersonation protection to counter payroll fraud.