search

Payroll Data Security: Protecting Sensitive Employee Information

7/6/2026

Payroll holds the highest-value data set in most organizations: Social Security numbers, dates of birth, home addresses, bank account and routing numbers, compensation for every employee, and — through garnishment orders, disability arrangements, and leave records — information that is medical-adjacent and legally protected.

It is also targeted by two attacks that are cheap to attempt, highly effective, and specifically designed around how payroll departments work. Both are preventable by procedure rather than technology.

Attack 1: Payroll Diversion

How it works. An email arrives, apparently from an employee, requesting a change to their direct deposit account. The tone is casual and plausible. The account details are the attacker's. One pay period later the wages are gone.

Why it succeeds. The request looks routine, payroll processes many of them, and the request often arrives on a Friday or immediately before a payroll deadline when scrutiny is lowest. Attackers frequently reference real details harvested from social media or a prior breach, and sometimes compromise the employee's actual email account, which defeats sender verification entirely.

Recovery is limited. Once an ACH credit settles into an attacker-controlled account, funds are typically withdrawn immediately. The employer generally still owes the employee their wages, which means the loss is the employer's.

The controls that stop it:

  • Never accept a bank change by email alone. This single rule prevents the attack.
  • Verify through a different channel than the one the request arrived on — a phone call to the number on file, not a number supplied in the request.
  • Hold the first payment to a newly changed account for one cycle, or send a small verification amount.
  • Notify the employee at their on-file address and personal contact whenever bank details change, so an unauthorized change is reported quickly.
  • Review accounts shared by multiple employees, which can indicate either fraud or a legitimate family arrangement worth confirming.
  • Require in-system self-service changes with multi-factor authentication where available, rather than email requests at all.

Attack 2: The W-2 Phishing Request

How it works. An email apparently from an executive, or from someone claiming to be an auditor or tax preparer, asks payroll to send a file of employee Forms W-2 or a wage summary. It is urgent, it invokes authority, and it discourages verification.

Why it is worse than diversion. Diversion costs one employee's net pay. A successful W-2 request discloses the Social Security number, address, and full annual compensation of every employee — enabling large-scale tax refund fraud and identity theft, triggering breach notification obligations in every applicable state, and creating a lasting harm the employer cannot undo.

The controls:

  • Establish a standing rule that bulk employee tax or compensation data is never sent in response to an email request, without exception and regardless of who appears to be asking.
  • Verify any such request by voice with the purported requester, using a known number.
  • Train the specific scenario, not phishing generally. Staff need to recognize this exact request pattern.
  • Explicitly authorize refusal. The attack exploits reluctance to challenge apparent authority. Payroll staff must know that declining an executive's emailed request for W-2 data is expected behavior, not insubordination.
  • Encrypt and control any legitimate bulk transfer, with a defined process and named approvers.

That fourth point is the one organizations most often omit and most need. An employee who fears being reprimanded for questioning the CFO will comply.

Access Control

Least privilege. Access to compensation and personal data should be limited to those whose work requires it, and the boundaries should be explicit. Managers generally need their own team's information, not the full register. Finance needs aggregate figures, not individual detail.

Separate garnishment and leave information. Garnishment orders reveal financial distress; disability and leave records are medical-adjacent. Both should be restricted more tightly than general payroll data, and neither should be visible to the employee's supervisor.

Store Forms I-9 separately from personnel files — an inspection is limited to the I-9 and related documents, and commingling exposes the entire file. See our I-9 compliance guide.

Remove access promptly on departure or role change. An active account for a departed payroll administrator is a serious control failure, and it is one of the most common findings in any access review.

Log and review access. Particularly access to records the person has no business reason to view.

Multi-factor authentication on the payroll system, the banking portal, and email — email being the account whose compromise enables both attacks above.

Vendor and Third-Party Risk

Payroll data reaches more third parties than most departments realize: the payroll provider, the timekeeping system, benefit carriers, retirement recordkeepers, the garnishment remittance processor, background check vendors, and the bank.

For each, establish:

  • What data they receive, and whether it is more than they need
  • Where it is stored and processed
  • Their security posture, and whether an independent assessment exists
  • Sub-processors who also receive the data
  • Who bears responsibility for a breach, contractually
  • Their breach notification obligation to you, and the timeframe
  • What happens to your data at contract termination — retention period and deletion

Note that a vendor breach is generally your notification obligation to your employees. A contract that allocates cost does not transfer the statutory duty or the reputational consequence.

Breach Notification

Payroll data sits squarely within state breach notification statutes, and the obligations are real:

  • Every state has a notification statute, and their triggers, timelines, and content requirements differ
  • Notification is generally owed based on the residence of the affected individuals, so a single breach can trigger obligations in many states
  • Several states require notification to the attorney general or another agency in addition to individuals
  • Timelines are short in a growing number of states
  • Some states require offering credit monitoring
  • Where the data includes health-related information, additional regimes may apply

Two practical implications: identify now which states your employees reside in, since that determines the applicable statutes, and have counsel identified in advance. A breach is not the moment to research notification requirements across fifteen states.

Continuity Overlaps With Security

A ransomware event is both a security incident and an operational one — you may be unable to run payroll, which is a wage payment violation in most states regardless of cause.

Minimum preparation:

  • Offline, tested backups of employee, rate, and year-to-date data
  • Access credentials held by more than one person, stored securely
  • A manual check capability
  • Knowledge of how to deposit taxes without the usual system
  • An employee communication plan

See cybersecurity and keeping payroll processing going during an outage and our disaster recovery guide.

The Insider Consideration

Most payroll security discussion assumes an external attacker. Internal misuse is at least as common and considerably harder to detect.

Controls that address it: least-privilege access, access logging with review, separation of the person who enters changes from the person who releases payroll, review of bank account changes, and periodic reconciliation of HR's active roster against the payroll register.

The last three are the same controls that prevent ghost employee fraud, which is not a coincidence — the access that enables data misuse is the access that enables payment fraud. See our segregation of duties guide.

A Practical Control Set

  • [ ] Never accept a bank account change by email alone
  • [ ] Verify account changes through a different channel, using a number on file
  • [ ] Hold the first payment to a newly changed account
  • [ ] Notify employees whenever bank details change
  • [ ] Never send bulk W-2 or wage data in response to an email request
  • [ ] Verify any such request by voice, and explicitly authorize staff to refuse
  • [ ] Multi-factor authentication on payroll, banking, and email
  • [ ] Least-privilege access, with garnishment and leave data restricted further
  • [ ] Store Forms I-9 separately from personnel files
  • [ ] Remove access on departure or role change, and audit accounts periodically
  • [ ] Log and review access to sensitive records
  • [ ] Inventory every third party receiving payroll data, with breach terms in contract
  • [ ] Identify the states your employees reside in, for breach notification planning
  • [ ] Identify breach counsel in advance
  • [ ] Maintain offline tested backups and a manual payroll capability
  • [ ] Encrypt data in transit and at rest, including any file transfer
  • [ ] Train the specific attack scenarios, not phishing generally

Responding to a Suspected Incident

The first hour matters, and the instinct to investigate quietly before escalating usually makes things worse.

If a bank change is reported as unauthorized:

  1. Stop the payment if it has not settled. ACH reversal is possible within narrow windows and only for permitted reasons — act immediately rather than after confirming details.
  2. Contact your bank and the payroll provider at once. Speed is the only variable you control.
  3. Restore the correct account and confirm it directly with the employee by voice.
  4. Pay the employee. They are owed their wages regardless of the loss, and delaying is a wage payment violation.
  5. Check whether other employees were targeted. These attacks arrive in batches, so review all recent account changes.
  6. Preserve the email, including headers, and determine whether the employee's account was compromised — if it was, this is a broader incident.

If bulk employee data was disclosed:

  1. Escalate immediately to counsel and leadership. Do not attempt to assess the scope alone.
  2. Preserve everything — the request, the response, what was sent, and to where.
  3. Determine exactly which employees and which data elements were included. Notification obligations depend on this.
  4. Identify the states where affected employees reside, since notification duties follow residence and one incident can trigger obligations in many states with differing timelines.
  5. Do not notify anyone before counsel has advised, since content and timing are statutorily specified.
  6. Expect tax refund fraud. Where Social Security numbers and wage data were disclosed, affected employees may need to take protective steps with the IRS, and the employer typically bears the cost of credit monitoring.

In both cases, document the timeline — when it was discovered, by whom, what was done, and when. That record is the basis for demonstrating a reasonable response, and it cannot be reconstructed reliably afterward.

Frequently Asked Questions

What is payroll diversion fraud?

An attack in which someone impersonating an employee — often by email, sometimes from the employee's actual compromised account — requests a change to their direct deposit details, redirecting wages to an attacker-controlled account. Funds are typically withdrawn immediately and recovery is limited, while the employer generally still owes the employee their wages, making the loss the employer's. Never accepting a bank change by email alone prevents it.

How do you prevent W-2 phishing attacks?

Establish a standing rule that bulk employee tax or compensation data is never sent in response to an email request, regardless of who appears to be asking, and verify any such request by voice using a known number. Critically, explicitly authorize staff to refuse — the attack works by exploiting reluctance to challenge apparent executive authority, so employees must know that declining is expected rather than insubordinate.

Who should have access to payroll data?

Only those whose work requires it, with explicit boundaries. Managers generally need their own team's information rather than the full register, and finance needs aggregate figures rather than individual detail. Garnishment orders and leave records warrant tighter restriction than general payroll data, and neither should be visible to the employee's supervisor. Forms I-9 should be stored separately from personnel files entirely.

Is an employer liable for a payroll vendor's data breach?

The notification obligation to affected employees is generally the employer's regardless of where the breach occurred, and a contract allocating cost does not transfer the statutory duty or the reputational consequence. Establish contractually what data each vendor receives, where it is processed, which sub-processors are involved, their obligation to notify you and within what timeframe, and what happens to your data at termination.

What are the breach notification requirements for payroll data?

Every state has a notification statute with differing triggers, timelines, and content requirements, and the obligation generally follows the residence of affected individuals — so one breach can trigger obligations in many states simultaneously. Several states also require notification to the attorney general or another agency, some require offering credit monitoring, and timelines are short in a growing number of states. Identify where your employees reside before you need to know.

How does payroll security relate to fraud prevention?

They rely on the same controls, because the access that enables data misuse is the access that enables payment fraud. Least-privilege access, access logging with review, separation of the person entering changes from the person releasing payroll, review of bank account changes, and reconciliation of HR's active roster to the payroll register all serve both purposes simultaneously.

Going Deeper

Breach notification statutes and their timelines change, and vendor security postures should be reassessed periodically. Identify your employees' states of residence and your breach counsel in advance, and treat the two email-based attacks above as procedural problems rather than technology problems.

PayrollTrainingCenter.com
mailing address
9715 Rod Road Suite A Alpharetta, GA 30022
phone1-770-410-1219 emailsupport@PayrollTrainingCenter.com
Trusted Provider Of
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Banking Mortgage Insurance Financial Services For TPAs Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials SeminarsWebinars All Payroll Subjects
Facebook Copyright PayrollTrainingCenter.com 2026