The mechanism is four steps and the third is the one worth memorizing. IC3's description is compact enough to follow exactly. First, the attacker sends phishing emails "designed to capture an employee's login credentials", aimed at the employee rather than at the employer's finance department. Second, once the credentials work, they are used to reach the employee's payroll account "in order to change their bank account information". Third, and this is the part that separates this scheme from an ordinary account compromise, "rules are added by the cybercriminal to the employee's account preventing the employee from receiving alerts regarding direct deposit changes". Fourth, the deposits are redirected to an account the criminal controls, "which is often a prepaid card". IC3 reported the institutions most affected as education, healthcare and commercial airway transportation.
Alert suppression is the reason this works, and it is the reason the usual advice fails. A change confirmation would otherwise reach the employee, and the fact that the scheme includes a step to stop it is the attacker's own admission that the notice is the control that works. Once it is switched off, the absence of a warning is engineered rather than reassuring, and the earliest reliable detection is not an alert at all: it is checking that the deposit landed, on the day it was supposed to.
The entry route has moved on since that 2018 description, and the FBI has said so. An April 2025 IC3 announcement warns that criminals are buying search-engine advertisements that impersonate employee self-service websites, so a worker searching for their own payroll portal lands on a copy of it and hands over the login there. The FBI states the consequence directly: if an employee payroll account, unemployment account, health savings account or retirement account is reached this way, "the cyber criminal can change the direct deposit information and redirect future payments". The same announcement describes a second way of burying the warning, which is flooding the victim with thousands of spam emails so a genuine notice of account compromise is not noticed. So the phishing email of the 2018 description is not the only way in, and the destination is the same.
There is no current loss figure for the credential-access version, and that is a measurement rather than an assumption. IC3's 2025 Internet Crime Report was searched in full for this page: the words "payroll" and "direct deposit" appear nowhere in it, so the scheme is not broken out as a category there. Quoting a business email compromise total instead would attach a number from a much larger category to a narrower one. The one figure the FBI has published is for a different, adjacent variant, and it is dated: in its 2019 announcement on business email compromise, IC3 counted 1,053 complaints of the payroll-diversion scheme in its BEC form between January 1, 2018 and June 30, 2019, with a total reported loss of $8,323,354 and an average of $7,904 per complaint.
That adjacent variant is worth knowing because it reaches the employer rather than the employee, and the FBI treats it as a different scheme. In it, a company's human resources or payroll department receives a spoofed email appearing to come from an employee asking to update their direct deposit details, and the new details generally lead to a prepaid card. IC3 says plainly that this "is different from the payroll diversion scheme in which the subject gains access to an employee's direct deposit account and alters the routing to another account", though the two are often linked in practice, since a phishing round that harvests employee credentials is what makes the spoofed requests look legitimate. The control that stops the employer-side version is out-of-band verification of any banking change, which the 2019 announcement puts as using a secondary channel or two-factor authentication to verify a request to change account information.
Timing is what turns a small theft into a large one. A payroll change made today generally takes effect on the next cycle, so on a semimonthly payroll an edit made shortly after a pay date does not show up until the following one, as much as two weeks later. If the employee assumes a delay, waits, and raises it only after a second missing deposit, two full periods of pay have gone. Nothing about that sequence requires the employee to be careless; it requires only that a missing deposit look, for a day or two, like a bank holiday.
The controls IC3 recommends split cleanly between what an employee can do and what only an employer can do. On the employee's side: never supply login credentials or personal information in response to an email; hover over links to see the real address before clicking; forward suspicious requests for personal information to information technology or human resources; and make sure the password used for payroll differs from the one used anywhere else, since IC3 singles out reuse between payroll logins and "other purposes, such as employee surveys". On the employer's side: educate the workforce about the scheme specifically; apply heightened scrutiny to bank information "initiated by employees seeking to update or change direct deposit credentials"; monitor logins outside normal business hours; restrict internet access on systems handling sensitive information or require two-factor authentication for them; and run only required processes on those systems. That scrutiny control is written broadly enough to cover a change request arriving by email rather than through the portal, which is the variant that reaches HR rather than the employee.
Who ends up out of pocket is genuinely unsettled, and pretending otherwise would be worse than saying so. The money never reaches the employee's own account, so this is not the ordinary case of an unauthorized transfer out of a consumer account, and nothing found in the federal consumer-transfer rules allocates this particular loss between the employer and the employee. In practice the question is answered by the employer's own policy, by state wage payment law, and sometimes by whose systems were compromised. That makes the first phone call the important one: an employer told within hours may be able to recall or reverse the payment before it is withdrawn, which no later remedy reliably replaces.
Related schemes are distinct and are covered separately here. Phishing is the technique that supplies the credentials rather than the fraud itself. An account takeover is a criminal seizing control of a financial account the victim already holds, which shares the change-the-alerts signature but targets the account rather than the payroll instruction. And where the credentials came from a breach, the exposure usually reaches further than payroll. Reporting and recovery for any of these run through the general fraud page.