Your Paycheck Never Arrived: The Fake Payroll Portal and the Quietly Changed Direct Deposit
August 26, 2026
The theft is a single edited field in a website you log into twice a year — which is why the average victim discovers it a fortnight later, standing in front of a cash machine.
Almost every scam we write about takes money out of somewhere. A fake bill-pay page takes a card number. A tech-support caller takes a remote-control session and then a bank transfer. A recovery scammer takes a fee for money that was never coming back. In all of them, the moment of loss is a moment you were present for, even if you did not understand it at the time.
This one is different, and the difference is the whole problem. Nothing is taken. One field is edited — the bank account your wages are paid into — inside a website you log into perhaps twice a year. Nothing on your computer breaks. No money leaves any account you own. Your employer pays you on time, in full, exactly as they always do. The money simply goes somewhere else, and you find out on payday.
By then the pay run has settled, the account it landed in has already been emptied, and you are having a conversation with your employer that neither of you has ever had before. This piece is about how it happens, the one line on your pay stub that would have shown it, what to do in the first hour if it has already happened, and — for the small businesses we look after — the unglamorous policy that actually stops it, which is not a piece of software.
The FBI wrote this one down, and it is worth reading what they actually said
On April 24, 2025, the FBI's Internet Crime Complaint Center published a public service announcement titled "Cyber Criminals Impersonating Employee Self-Service Websites to Steal Victim Information and Funds." It opens plainly: "The FBI is warning the public that cyber criminals are targeting users of employee self-service websites owned by companies and government services."
The route in is a search result. In the FBI's description, "the fraudulent URL appears at the top of search results and mimics the legitimate business URL with minimal differences" — a criminal buys an advert against the name of a payroll or benefits portal, the advert sits above the real thing, and the page it leads to is a copy good enough that typing your password into it feels like an ordinary Tuesday.
What happens next is the sentence to remember, because it names every account this touches rather than just payroll: "If an employee payroll account, unemployment account, health savings account, or retirement account is accessed, the cyber criminal can change the direct deposit information and redirect future payments." Payroll is the famous one. Your HSA, your 401(k) and a state unemployment claim are the same shape of target, and they are checked even less often.
The second route does not involve you at all
There is a version of this where you never see a fake website, never mistype a URL and do nothing wrong, and it is the one that hits small businesses hardest. Instead of stealing your login, the criminal simply emails whoever runs payroll and asks them to change your bank details.
The message comes from a free email account opened in your name, or from a display name spoofed to read like yours, or — worst case — from your actual mailbox, because the password came from a breach and nobody had turned on multi-factor authentication. It is short, friendly and slightly apologetic. I have switched banks, can you update my direct deposit before Friday, here are the new details, thanks so much. There is nothing technical about it and no malware anywhere.
The reason this works is structural rather than technical. At a company of nine people, the person who processes payroll also does the invoices, the supplier payments and the school-run, and a bank-detail change from a colleague is one of the most ordinary requests in their inbox. There is no fraud department to escalate to. There is nothing to detect, because nothing malicious has happened yet — a person has simply been asked to do their job.
The one line on your pay stub that would have caught it
Here is the check, and it takes about fifteen seconds. Open your most recent pay stub and find the deposit line — on nearly every payroll system in use it prints the last four digits of the account the money went to, sometimes with the bank name beside it. Confirm those four digits are yours.
That single field is the only place in the entire transaction where the theft is visible. Everything else on the stub is correct and reassuring: your gross pay, your deductions, your net pay, the pay date. Your employer's system will tell them the payment was issued successfully, because it was. The money went precisely where the record said to send it. The record was edited.
This is the same discipline we keep landing on in scam after scam — go and look at an artefact you already possess rather than at whatever is currently in front of you. On a bill-pay scam the artefact is the paper bill or the back of the card. Here it is four digits on a stub you have been filing without reading for years. If they are not your four digits, stop reading this and skip to the first-hour section below.
Two practical notes. If you are paid twice a month, checking the stub each time costs you half a minute a month and closes the detection gap from a fortnight to a fortnight at worst — which sounds unimpressive until you compare it to the alternative, which is finding out when a direct debit bounces. And if your payroll system does not show the last four digits anywhere, log into the portal itself and read the bank details there, on a bookmark, not a search result.
Why multi-factor authentication is necessary here and not sufficient
Turn on multi-factor authentication for your payroll, HSA and retirement portals. It is the highest-value ten minutes available to you and it defeats the ordinary version of the stolen-password attack outright. We are not about to talk you out of it.
But it is worth being honest about the two ways it gets walked around, because "I have MFA" is doing a lot of load-bearing work in most people's sense of safety. The first is in the FBI's own advisory: "One social engineering tactic involves masquerading as a bank representative while calling the victim and asking for their one-time passcode." You typed your password into a convincing page, so the criminal has it; ninety seconds later a calm, professional person rings about suspicious activity and needs the code you were just sent to verify you. The code is real. The site asking for it is not.
The second is simpler and defeats MFA by never meeting it: the email route above. Nobody logs in at all. A well-configured portal with hardware keys and conditional access is entirely irrelevant when the change is made by a helpful human being on the other side of the building. This is why the small-business section below is about a phone call rather than a product.
The rule that survives both: nobody legitimate will ever ring you and ask you to read out a one-time passcode. Not your bank, not your payroll provider, not your IT support, not us. A code you did not just request is a burglar knocking to check you are out.
Turn the alerts on — then check nobody has turned them off
Most payroll and benefits portals will email you when your bank details are changed. That notification is the single best detector in this whole story, because it converts a fortnight of silence into a message that arrives within seconds of the theft. Go and find it in your portal's notification or security settings and make sure it is switched on, and make sure it points at an email address you actually read.
Now the part that makes this worth its own section. Criminals know that alert exists, and turning it off is often the second thing they do after changing the account. So switching it on is not a one-off task — it is a thing to confirm is still true, on the same visit where you check the four digits.
The same trick runs on your mailbox rather than the portal, and it is more common. If the criminal has your email password, they do not need to disable the alert at source; they only need to make sure you never see it. That is a mailbox rule, and it is the most under-checked hiding place in consumer and small-business tech. It gets its own section further down, because it is genuinely the thing we get called out for most often after an account compromise.
It has happened: the first hour, in order
Speed is the entire game here and the order matters, so do these in sequence rather than doing the most emotionally satisfying one first.
One: tell whoever runs payroll, by phone, now. Not email — phone. If your mailbox is the thing that was compromised, an email to payroll may be read and deleted by the person who stole from you before your employer ever sees it. Payroll needs to know within hours rather than days for the reason in the next section.
Two: change your payroll portal password, and change it from a device you trust, and do not reuse a password you have used elsewhere. Then change your email password, because the two are far more likely to be linked than they feel.
Three: check your mailbox for rules that are hiding things from you. Details below; do not skip this because the portal is the obvious victim. The mailbox is how they stay invisible.
Four: report it at ic3.gov. This is not a formality and it is not only for large sums. The FBI's Recovery Asset Team, set up in February 2018, exists specifically to contact the bank that received a fraudulent transfer and ask for the funds to be frozen, and its ability to do anything at all falls away sharply with time. Filing the same day genuinely matters; filing three weeks later is paperwork.
Five: put your bank on notice and watch the account, even though the money never touched it. The bank details you handed over on a fake portal are frequently accompanied by enough personal information to be useful somewhere else, and the retirement and HSA accounts named in the FBI advisory are worth logging into and checking while you are in the mood.
The five-day window nobody tells employees about
This is the fact that changes what your phone call to payroll should sound like, and we have never seen it explained to the person it helps most.
A direct deposit is an ACH payment, and ACH payments run under the Nacha Operating Rules. Those rules let the originator of a payment — your employer, through their bank or payroll provider — send a reversal to claw back an erroneous entry, and the definition of erroneous explicitly covers a payment sent to an unintended account. That is exactly what your paycheck was.
The catch is the clock. A reversal has to be transmitted so that it reaches the receiving bank within five banking days following the settlement date of the original entry. Banking days, not calendar days — a weekend and a public holiday eat that window fast, and a Friday payday discovered the following Wednesday is already most of the way through it.
So the useful thing to say when you ring payroll is not "my pay has not arrived, can you look into it." It is "my direct deposit was changed without my authorisation and the funds went to the wrong account — please ask your bank or payroll provider about an ACH reversal today, because there is a five-banking-day limit from the settlement date." That sentence turns a support ticket into a deadline, and the person you are talking to may well not know the deadline exists.
Be realistic about the odds. A reversal is a request, not a guarantee: it depends on the receiving bank, and on whether anything is left in an account that was very probably drained within hours. It is worth doing immediately and it is worth doing alongside the IC3 report rather than instead of it. But a window you used and lost is a different outcome from a window you did not know about.
Check your mailbox for rules, not just your password
When an email account is used in this kind of fraud, changing the password is the part everyone does and the part that is least likely to be sufficient on its own. The criminal's problem is not access — they already had that. Their problem is that you will eventually notice, and the standard solution is a mailbox rule that quietly disposes of the evidence.
Microsoft's own guidance on compromised accounts describes the behaviour precisely: attackers set rules to hide incoming mail in the compromised mailbox to obscure their activity, deleting messages, moving them into a folder nobody opens — the RSS Feeds folder is a documented favourite — or forwarding them to an outside address. The rules are keyed to words like invoice, phish, suspicious, do not reply. A rule matching "payroll" or "direct deposit" will make your employer's confirmation email vanish before you see it.
On a personal account, open your mail provider's settings and read every rule and every forwarding address, and be suspicious of anything you do not remember creating — especially a rule with a blank or single-character name, which is a deliberate trick to make it hard to see in a list. Check forwarding separately from rules; they are different settings and people routinely check one and not the other.
On Microsoft 365, the important word is hidden. Some rules do not appear in Outlook at all and only show up to an administrator running Get-InboxRule with the -IncludeHidden switch, checking each rule's RedirectTo and forwarding values for anything non-blank. If that sentence means nothing to you, that is fine and it is precisely the sort of thing to hand to us or to whoever manages your mail — but do have somebody look, because "I changed the password and it seemed fine" is how a compromise lasts nine months.
Are you still owed the money?
This is the first question every victim asks and we are going to answer it carefully, because it is a legal question rather than a technical one and the honest answer has an "it depends" in it.
What is clear is the starting point. In California, direct deposit is not something an employer may simply do — Labor Code section 213(d) permits wages to be deposited into an employee's account at a bank, savings and loan association or credit union "provided that the employee has voluntarily authorized that deposit." Your authorisation is the thing that makes the arrangement lawful, which means a change to those details made by somebody else is not an administrative correction. It is a change to an authorisation you never gave.
Where it goes from there depends on the facts — how the change was made, what the employer did or did not verify, and what is recoverable. We are a computer repair company and not your lawyer, and anybody who tells you confidently how this resolves without knowing the details is guessing. What we can tell you is where the conversation goes if it stalls: in California, unpaid-wage disputes are handled by the Labor Commissioner's Office, part of the Department of Industrial Relations, and filing a wage claim is a free process that does not require a lawyer. Ask your employer first, in writing, and keep the pay stub with the wrong four digits on it.
One thing not to do while you wait: do not accept help from anyone who contacts you offering to recover the funds for a fee. A person who has just lost a paycheck and is publicly upset about it is exactly the profile the follow-on recovery scam looks for, and we have a whole article about that second wave.
If you run the payroll: the control that works is a phone call
Everything above is written for the employee. This section is for the eight-person office, the dental practice, the contractor with a bookkeeper — the businesses that make up most of our small-business work and that have no HR department to absorb this.
The control is a callback rule, and it is one sentence long: no bank-detail change is ever made on the strength of an email alone. Any request to change direct deposit details, from anyone, is confirmed by voice on a number you already hold for that person, before the change is made.
The words "already hold" carry the entire weight. Not the number in the email signature, not a number in the message body, not a number that arrived attached to the request — the number in your own records, the one you have rung before. A criminal who can send a convincing email can also put a phone number in it, and will happily answer when you dial it and confirm they are who they say they are.
Three things make the rule stick rather than erode. Write it down and tell the whole team, so the person who processes payroll is enforcing a policy rather than personally implying they do not trust a colleague — that social awkwardness is the real reason callbacks get skipped. Apply it to everyone including the owner, because "urgent, from the boss, do not call me I am in a meeting" is the oldest version of this attack and a rule with an exception at the top is not a rule. And make the change take effect on the next pay run rather than the current one, so the confirmation email has time to reach a real employee who can object.
Alongside the policy, three technical measures are worth the effort, in this order: multi-factor authentication on every mailbox and on the payroll system, no exceptions and especially not for whoever finds it annoying; alerting or a periodic check for mailbox forwarding rules, since that is where a compromise hides; and a review of who actually needs the permission to change bank details in your payroll system, which at most small businesses turns out to be fewer people than currently have it.
If your business has already been hit
Ring the payroll provider or the bank immediately and ask about a reversal, for the five-banking-day reason above. Then tell the affected employee by phone rather than email — their mailbox may be the compromised one — and file at ic3.gov the same day.
Then work out what else the intruder saw, because a mailbox that could request a bank-detail change could usually also read a great deal else. If employee tax data was exposed, the IRS runs a specific channel for exactly this and it is time-sensitive: a business that has lost W-2 or Social Security number data emails dataloss@irs.gov with the subject line "W2 Data Loss", giving the business name and EIN, a contact, a summary of what happened and how many employees are affected — and deliberately not attaching any employee personal data to that email. If you merely received the phishing attempt and did not fall for it, that goes to phishing@irs.gov with the subject "W2 Scam" instead. Reporting quickly is the point; the IRS can take protective steps for affected employees, but only while there is still time for those steps to matter.
Finally, do the boring reconstruction properly: reset the password and revoke the active sessions on the affected mailbox, remove any rules or forwarding the intruder added, check whether the same request went to anyone else in the company, and look at whether other bank details in your accounting system — suppliers, especially — were altered in the same visit. Payroll diversion and supplier-invoice diversion are the same crime with a different target, and the same access enables both.
The Southern California version of this
Two things about how our customers work make this land harder here than the national coverage suggests. The first is the hybrid office. A great deal of the professional work around Pasadena, Glendale and the San Fernando Valley now happens with the payroll portal reached from a kitchen table, over home Wi-Fi, on a personal laptop that also does the online shopping — which is the environment where a search result gets clicked instead of a bookmark, because the bookmark is on the work machine at the office.
The second is the seasonal employer. Across the Coachella Valley in particular, a large share of small-business staffing is seasonal and short-tenure — hospitality, events, landscaping, property services — and seasonal payroll is exactly the soil this grows in. New starters legitimately submit bank details for the first time, so a bank-detail change looks routine rather than exceptional; people are onboarded in a rush ahead of a season; and someone who works a single season may not have a colleague who would recognise that an email does not sound like them. If you run that kind of payroll, the callback rule is not optional politeness, it is the only thing standing between you and a request that looks exactly like the twenty legitimate ones you processed last month.
The same logic applies to any household with someone on a benefits or unemployment portal rather than a payroll one. Those accounts hold a bank account number and are logged into rarely, which is the combination this attack is built for.
The short version
Get to your payroll, HSA and retirement portals through a bookmark you made yourself, never through a search result, and turn on multi-factor authentication on all of them. Nobody legitimate will ever phone you and ask you to read out a one-time code.
Check the last four digits of the deposit account on your pay stub each payday. It takes fifteen seconds and it is the only place the theft is visible, because everything else on the stub will be perfectly correct.
If a paycheck goes missing, ring payroll the same day, say the words "unauthorised direct deposit change" and "ACH reversal", and mention the five-banking-day limit from the settlement date. Then change both passwords, have someone check your mailbox for hidden rules and forwarding, and file at ic3.gov immediately — the recovery odds fall off a cliff with time.
And if you run payroll for a small business: no bank-detail change on the strength of an email, ever. Confirm by voice on a number you already had, apply the rule to the owner as well, and write it down so nobody has to feel rude enforcing it.
How we can help
A fair amount of the above you can do yourself, and if you do, we are glad. Where people call us is the part after the password change, when the question is no longer "how do I get back in" but "how do I know they are actually out" — reading a mailbox for hidden rules and forwarding addresses, checking which sessions and app passwords are still live, working out whether a compromise on one account has quietly spread to the ones that share its recovery address.
For small businesses we do the setup that makes the callback rule enforceable rather than aspirational: multi-factor authentication rolled out to everyone without the exceptions that usually get carved out for whoever complains loudest, alerting on mailbox forwarding rules, tidying up who has permission to change bank details, and a plain-English one-page policy for the person who actually runs payroll. None of it is expensive and none of it is interesting, which is roughly why it does not get done until something like this happens.
And if you are reading this because it already has happened, call us rather than emailing — for the same reason we told your employer to. We can look at the mailbox the same day and tell you what was seen, what was changed, and what still needs closing.
Keep reading
- You Went Looking for Them: Fake Bill-Pay Sites and Fake Support Numbers in Your Own Search Results
- Your Email Got Hacked? The Steps That Actually Lock the Intruder Out
- An Employee Left and Their Email Left With Them: What to Do, in the Right Order
- Your Password "Appeared in a Data Leak": What That Warning Means and What to Do
- Someone Says They Can Get Your Money Back? That's the Second Scam
- Is That Download Site Real? Fake "Official" Pages Now Outrank the Software They Copy
Free calculators
Service areas we cover
We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.
Call (626) 655-0020