Skip to content

Direct Deposit Switch Scam

A direct deposit switch scam is a scheme in which a criminal changes the bank account on file in an employer's payroll system so that an employee's pay is routed to an account the criminal controls. The FBI calls it payroll diversion. Its signature move is suppressing the alerts that would otherwise announce the change.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • The theft happens inside the payroll system, not at the bank. Nothing is withdrawn from the employee's account, because the money never arrives in it.
  • The FBI's Internet Crime Complaint Center uses a different name for it, payroll diversion, and asks victims to write that phrase in the body of a complaint.
  • The step that makes it work is alert suppression. The criminal adds rules to the account so the employee never sees the change confirmation.
  • Because the alerts are suppressed, the first signal is usually a paycheck that does not arrive, which can be a full pay cycle after the change.
  • Who absorbs the loss is not settled by any single federal rule, which is why telling the employer immediately matters more than anything else.

Definition

A direct deposit switch scam is a payroll fraud in which an attacker gains access to an employee's payroll or human resources account and edits the direct deposit instruction, replacing the employee's bank details with an account the attacker controls. The employer then pays wages exactly as instructed, to the wrong account, and the employee's pay simply does not appear.

The federal agency that tracks the scheme uses a different name for it. The FBI's Internet Crime Complaint Center titled its 2018 public service announcement "Cybercriminals Utilize Social Engineering Techniques To Obtain Employee Credentials To Conduct Payroll Diversion", and it closes by asking victims to "note payroll diversion in the body of the complaint". Payroll diversion is therefore the name to use when reporting, and direct deposit switch scam is the name it travels under everywhere else. They are one thing.

Advanced Explanation

The mechanism is four steps and the third is the one worth memorizing. IC3's description is compact enough to follow exactly. First, the attacker sends phishing emails "designed to capture an employee's login credentials", aimed at the employee rather than at the employer's finance department. Second, once the credentials work, they are used to reach the employee's payroll account "in order to change their bank account information". Third, and this is the part that separates this scheme from an ordinary account compromise, "rules are added by the cybercriminal to the employee's account preventing the employee from receiving alerts regarding direct deposit changes". Fourth, the deposits are redirected to an account the criminal controls, "which is often a prepaid card". IC3 reported the institutions most affected as education, healthcare and commercial airway transportation.

Alert suppression is the reason this works, and it is the reason the usual advice fails. A change confirmation would otherwise reach the employee, and the fact that the scheme includes a step to stop it is the attacker's own admission that the notice is the control that works. Once it is switched off, the absence of a warning is engineered rather than reassuring, and the earliest reliable detection is not an alert at all: it is checking that the deposit landed, on the day it was supposed to.

The entry route has moved on since that 2018 description, and the FBI has said so. An April 2025 IC3 announcement warns that criminals are buying search-engine advertisements that impersonate employee self-service websites, so a worker searching for their own payroll portal lands on a copy of it and hands over the login there. The FBI states the consequence directly: if an employee payroll account, unemployment account, health savings account or retirement account is reached this way, "the cyber criminal can change the direct deposit information and redirect future payments". The same announcement describes a second way of burying the warning, which is flooding the victim with thousands of spam emails so a genuine notice of account compromise is not noticed. So the phishing email of the 2018 description is not the only way in, and the destination is the same.

There is no current loss figure for the credential-access version, and that is a measurement rather than an assumption. IC3's 2025 Internet Crime Report was searched in full for this page: the words "payroll" and "direct deposit" appear nowhere in it, so the scheme is not broken out as a category there. Quoting a business email compromise total instead would attach a number from a much larger category to a narrower one. The one figure the FBI has published is for a different, adjacent variant, and it is dated: in its 2019 announcement on business email compromise, IC3 counted 1,053 complaints of the payroll-diversion scheme in its BEC form between January 1, 2018 and June 30, 2019, with a total reported loss of $8,323,354 and an average of $7,904 per complaint.

That adjacent variant is worth knowing because it reaches the employer rather than the employee, and the FBI treats it as a different scheme. In it, a company's human resources or payroll department receives a spoofed email appearing to come from an employee asking to update their direct deposit details, and the new details generally lead to a prepaid card. IC3 says plainly that this "is different from the payroll diversion scheme in which the subject gains access to an employee's direct deposit account and alters the routing to another account", though the two are often linked in practice, since a phishing round that harvests employee credentials is what makes the spoofed requests look legitimate. The control that stops the employer-side version is out-of-band verification of any banking change, which the 2019 announcement puts as using a secondary channel or two-factor authentication to verify a request to change account information.

Timing is what turns a small theft into a large one. A payroll change made today generally takes effect on the next cycle, so on a semimonthly payroll an edit made shortly after a pay date does not show up until the following one, as much as two weeks later. If the employee assumes a delay, waits, and raises it only after a second missing deposit, two full periods of pay have gone. Nothing about that sequence requires the employee to be careless; it requires only that a missing deposit look, for a day or two, like a bank holiday.

The controls IC3 recommends split cleanly between what an employee can do and what only an employer can do. On the employee's side: never supply login credentials or personal information in response to an email; hover over links to see the real address before clicking; forward suspicious requests for personal information to information technology or human resources; and make sure the password used for payroll differs from the one used anywhere else, since IC3 singles out reuse between payroll logins and "other purposes, such as employee surveys". On the employer's side: educate the workforce about the scheme specifically; apply heightened scrutiny to bank information "initiated by employees seeking to update or change direct deposit credentials"; monitor logins outside normal business hours; restrict internet access on systems handling sensitive information or require two-factor authentication for them; and run only required processes on those systems. That scrutiny control is written broadly enough to cover a change request arriving by email rather than through the portal, which is the variant that reaches HR rather than the employee.

Who ends up out of pocket is genuinely unsettled, and pretending otherwise would be worse than saying so. The money never reaches the employee's own account, so this is not the ordinary case of an unauthorized transfer out of a consumer account, and nothing found in the federal consumer-transfer rules allocates this particular loss between the employer and the employee. In practice the question is answered by the employer's own policy, by state wage payment law, and sometimes by whose systems were compromised. That makes the first phone call the important one: an employer told within hours may be able to recall or reverse the payment before it is withdrawn, which no later remedy reliably replaces.

Related schemes are distinct and are covered separately here. Phishing is the technique that supplies the credentials rather than the fraud itself. An account takeover is a criminal seizing control of a financial account the victim already holds, which shares the change-the-alerts signature but targets the account rather than the payroll instruction. And where the credentials came from a breach, the exposure usually reaches further than payroll. Reporting and recovery for any of these run through the general fraud page.

Used in a Sentence

“Payroll had processed the change before the cycle closed, so by the time Marguerite realized her salary had not arrived, the direct deposit switch scam had already taken one full pay period.”

How It Works

From the employee's side the sequence looks like this. A convincing email asks them to sign in to the payroll or benefits portal, usually about something routine such as a tax form or an open enrollment deadline. The link goes to a page that looks right and captures the login. Nothing visible happens. Behind the scenes the banking details are edited and the notification rules are changed. On payday the deposit does not arrive.

A hypothetical example of why the loss is usually more than one paycheck. Yusuf is paid semimonthly, on the 15th and the last day of the month, and nets $2,850 a period. An attacker edits his banking details on the 3rd. The change lands on the 15th cycle, so the first missing deposit is on the 15th, 12 days after the compromise and with no alert because the alerts were turned off.

Yusuf assumes a processing delay, waits over the weekend and calls payroll on the following Monday, by which time the money has been withdrawn. If he had instead waited for the month-end cycle to see whether the problem repeated, the loss would be 2 × $2,850 = $5,700. The arithmetic is simple; the lesson is the calendar. A missing deposit is worth a same-day phone call rather than a wait-and-see, precisely because the scheme's design has removed every other warning.

Pros and Cons

A payroll diversion has no upside, so what follows is what actually reduces exposure and what those protections do not reach.

What genuinely reduces exposure

  • A payroll password used nowhere else, because the credentials that open the portal are usually harvested somewhere other than payroll.
  • Two-factor authentication on the payroll portal, which makes a stolen password insufficient on its own.
  • Confirming that each deposit actually landed on the day it was due, which replaces the alert the scheme is built to suppress.
  • Opening the payroll portal periodically to look at the bank details on file and at any notification rules you did not create.
  • An employer control requiring out-of-band confirmation, a call to a number already on file, before any banking change takes effect.

What those protections do not reach

  • The absence of an alert, which proves nothing here, because removing the alerts is step three of the scheme.
  • Your own bank, which did nothing wrong and can do very little, since no transaction touched your account.
  • The first pay cycle, which is usually already gone by the time anyone notices, and sometimes the second as well.
  • Money already withdrawn from a prepaid account, where recovery depends almost entirely on how fast the payment was flagged.
  • The allocation of the loss between employer and employee, which no single federal rule settles.

People Also Asked

Answers to the most frequently asked questions.

Why does the FBI call it payroll diversion?
Because the agency names the scheme by what it does to the payment rather than by what it does to the enrollment. The FBI's Internet Crime Complaint Center published its warning under the title "Cybercriminals Utilize Social Engineering Techniques To Obtain Employee Credentials To Conduct Payroll Diversion" and asks victims to write "payroll diversion" in the body of a complaint so it is routed correctly. Employers and employees generally say direct deposit switch scam. Use the FBI's phrase when you report.
How would I know my direct deposit had been switched?
Usually because a deposit does not arrive, and that is by design. IC3 describes the attacker adding rules to the employee's account that prevent alerts about direct deposit changes from reaching them, so the confirmation email you would expect never appears. The reliable check is not waiting for a notification but confirming that each deposit actually landed on the day it was due, and periodically opening the payroll portal to look at the bank details on file.
If my paycheck was stolen this way, does my employer have to pay me again?
There is no single federal rule that answers this, and anyone who tells you otherwise is guessing. The money never reached your account, so it is not the ordinary case of an unauthorized transfer out of a consumer account. In practice the answer comes from your employer's policy, from your state's wage payment law, and sometimes from whose systems were compromised. Raise it with payroll in writing the same day, because a fast recall attempt is worth more than an argument about liability later.
What should I do the moment I notice a missing paycheck?
Call payroll rather than emailing, and ask them to check the bank details on file and to attempt a recall of the payment. Then change the payroll portal password, and change it anywhere else you used the same one. Look inside the portal and your email for rules or filters you did not create, because removing the attacker's alert suppression is what stops the next cycle going the same way. Reporting channels and the recovery steps that follow are covered on the fraud page.
How is this different from an account takeover?
An account takeover is a criminal gaining control of a financial account you already have and moving money out of it. A direct deposit switch scam never touches your bank account at all: it changes an instruction held by your employer, so the money is delivered somewhere else and your balance simply never rises. The two share a signature, which is that the attacker's first real move is to switch off the notifications, and they differ in who holds the compromised system.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Federal Bureau of Investigation, Internet Crime Complaint Center. "Cybercriminals Utilize Social Engineering Techniques To Obtain Employee Credentials To Conduct Payroll Diversion (Alert I-091818-PSA)."
  2. Federal Bureau of Investigation, Internet Crime Complaint Center. "Internet Crime Report 2025."
  3. Federal Bureau of Investigation, Internet Crime Complaint Center. "Cyber Criminals Impersonating Employee Self-Service Websites to Steal Victim Information and Funds (Alert I-042425-PSA)."
  4. Federal Bureau of Investigation, Internet Crime Complaint Center. "Business Email Compromise: The $26 Billion Scam (Alert I-091019-PSA)."
  5. Federal Trade Commission. "How To Recognize and Avoid Phishing Scams."

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor