Payroll holds the highest-value data set in most organizations: Social Security numbers, dates of birth, home addresses, bank account and routing numbers, compensation for every employee, and — through garnishment orders, disability arrangements, and leave records — information that is medical-adjacent and legally protected.
It is also targeted by two attacks that are cheap to attempt, highly effective, and specifically designed around how payroll departments work. Both are preventable by procedure rather than technology.
How it works. An email arrives, apparently from an employee, requesting a change to their direct deposit account. The tone is casual and plausible. The account details are the attacker's. One pay period later the wages are gone.
Why it succeeds. The request looks routine, payroll processes many of them, and the request often arrives on a Friday or immediately before a payroll deadline when scrutiny is lowest. Attackers frequently reference real details harvested from social media or a prior breach, and sometimes compromise the employee's actual email account, which defeats sender verification entirely.
Recovery is limited. Once an ACH credit settles into an attacker-controlled account, funds are typically withdrawn immediately. The employer generally still owes the employee their wages, which means the loss is the employer's.
The controls that stop it:
How it works. An email apparently from an executive, or from someone claiming to be an auditor or tax preparer, asks payroll to send a file of employee Forms W-2 or a wage summary. It is urgent, it invokes authority, and it discourages verification.
Why it is worse than diversion. Diversion costs one employee's net pay. A successful W-2 request discloses the Social Security number, address, and full annual compensation of every employee — enabling large-scale tax refund fraud and identity theft, triggering breach notification obligations in every applicable state, and creating a lasting harm the employer cannot undo.
The controls:
That fourth point is the one organizations most often omit and most need. An employee who fears being reprimanded for questioning the CFO will comply.
Least privilege. Access to compensation and personal data should be limited to those whose work requires it, and the boundaries should be explicit. Managers generally need their own team's information, not the full register. Finance needs aggregate figures, not individual detail.
Separate garnishment and leave information. Garnishment orders reveal financial distress; disability and leave records are medical-adjacent. Both should be restricted more tightly than general payroll data, and neither should be visible to the employee's supervisor.
Store Forms I-9 separately from personnel files — an inspection is limited to the I-9 and related documents, and commingling exposes the entire file. See our I-9 compliance guide.
Remove access promptly on departure or role change. An active account for a departed payroll administrator is a serious control failure, and it is one of the most common findings in any access review.
Log and review access. Particularly access to records the person has no business reason to view.
Multi-factor authentication on the payroll system, the banking portal, and email — email being the account whose compromise enables both attacks above.
Payroll data reaches more third parties than most departments realize: the payroll provider, the timekeeping system, benefit carriers, retirement recordkeepers, the garnishment remittance processor, background check vendors, and the bank.
For each, establish:
Note that a vendor breach is generally your notification obligation to your employees. A contract that allocates cost does not transfer the statutory duty or the reputational consequence.
Payroll data sits squarely within state breach notification statutes, and the obligations are real:
Two practical implications: identify now which states your employees reside in, since that determines the applicable statutes, and have counsel identified in advance. A breach is not the moment to research notification requirements across fifteen states.
A ransomware event is both a security incident and an operational one — you may be unable to run payroll, which is a wage payment violation in most states regardless of cause.
Minimum preparation:
See cybersecurity and keeping payroll processing going during an outage and our disaster recovery guide.
Most payroll security discussion assumes an external attacker. Internal misuse is at least as common and considerably harder to detect.
Controls that address it: least-privilege access, access logging with review, separation of the person who enters changes from the person who releases payroll, review of bank account changes, and periodic reconciliation of HR's active roster against the payroll register.
The last three are the same controls that prevent ghost employee fraud, which is not a coincidence — the access that enables data misuse is the access that enables payment fraud. See our segregation of duties guide.
The first hour matters, and the instinct to investigate quietly before escalating usually makes things worse.
If a bank change is reported as unauthorized:
If bulk employee data was disclosed:
In both cases, document the timeline — when it was discovered, by whom, what was done, and when. That record is the basis for demonstrating a reasonable response, and it cannot be reconstructed reliably afterward.
An attack in which someone impersonating an employee — often by email, sometimes from the employee's actual compromised account — requests a change to their direct deposit details, redirecting wages to an attacker-controlled account. Funds are typically withdrawn immediately and recovery is limited, while the employer generally still owes the employee their wages, making the loss the employer's. Never accepting a bank change by email alone prevents it.
Establish a standing rule that bulk employee tax or compensation data is never sent in response to an email request, regardless of who appears to be asking, and verify any such request by voice using a known number. Critically, explicitly authorize staff to refuse — the attack works by exploiting reluctance to challenge apparent executive authority, so employees must know that declining is expected rather than insubordinate.
Only those whose work requires it, with explicit boundaries. Managers generally need their own team's information rather than the full register, and finance needs aggregate figures rather than individual detail. Garnishment orders and leave records warrant tighter restriction than general payroll data, and neither should be visible to the employee's supervisor. Forms I-9 should be stored separately from personnel files entirely.
The notification obligation to affected employees is generally the employer's regardless of where the breach occurred, and a contract allocating cost does not transfer the statutory duty or the reputational consequence. Establish contractually what data each vendor receives, where it is processed, which sub-processors are involved, their obligation to notify you and within what timeframe, and what happens to your data at termination.
Every state has a notification statute with differing triggers, timelines, and content requirements, and the obligation generally follows the residence of affected individuals — so one breach can trigger obligations in many states simultaneously. Several states also require notification to the attorney general or another agency, some require offering credit monitoring, and timelines are short in a growing number of states. Identify where your employees reside before you need to know.
They rely on the same controls, because the access that enables data misuse is the access that enables payment fraud. Least-privilege access, access logging with review, separation of the person entering changes from the person releasing payroll, review of bank account changes, and reconciliation of HR's active roster to the payroll register all serve both purposes simultaneously.
Breach notification statutes and their timelines change, and vendor security postures should be reassessed periodically. Identify your employees' states of residence and your breach counsel in advance, and treat the two email-based attacks above as procedural problems rather than technology problems.
Recommended Online Training Courses
Recommended Course(s)

1-770-410-1219
support@PayrollTrainingCenter.com


