Benchmark Benefits Consulting

Social Engineering & Fraud

“Can You Change My Direct Deposit?” The HR Request That Could Be a Fraud Attempt

A routine banking-change request can be an employee-impersonation attempt. HR and payroll need a calm, consistent way to decide when an administrative request has become an identity decision.

Published by Benchmark Benefits Consulting · Reviewed September 30, 2026

The request may look completely ordinary: “Hi, I recently changed banks. Can you update my direct deposit before the next payroll?” The name is familiar. The email looks professional. There may be no attachment, dramatic demand or obvious spelling error. There is just one problem: the employee may never have sent it.

Business email compromise and employee impersonation are not only problems for finance departments approving large wire transfers. The same technique can target HR and payroll: impersonate an employee, request a change to where money is sent, and rely on the organization’s normal workflow to complete the fraud.

The Royal Canadian Mounted Police identifies a specific BEC scheme in which a criminal uses a spoofed or compromised employee email account to ask payroll to change direct-deposit information, redirecting the employee’s pay to a fraudulent account. The FBI has also documented payroll-diversion schemes and recommends secondary channels or two-factor verification for account-information changes.

The central question: do not ask only, “Does this message look real?” Ask, “Have we independently verified that the person requesting this high-impact change is actually the employee?”

A familiar request can carry an unfamiliar risk

HR departments are built to help employees. An employee moves, changes a phone number, opens a bank account, updates a beneficiary, requests a password reset or asks a manager to modify access. Individually, these events can look administrative. Some of them, however, affect money, identity, sensitive information or system access and deserve a different level of attention.

Attackers understand organizational routines. Social engineering works by making a malicious request resemble something the recipient already expects to handle. The Canadian Centre for Cyber Security describes business email compromise as a social-engineering threat involving impersonation and trusted communication. The FBI similarly describes BEC as sophisticated fraud that exploits business relationships and communications.

The attacker does not always need to break the payroll platform. Sometimes the attacker only needs to persuade an authorized employee to make a legitimate change for the wrong person.

The reported numbers explain why routine verification matters

The FBI’s 2025 Internet Crime Report, released in 2026, records 24,768 BEC complaints and US$3,046,598,558 in reported BEC losses during 2025. Those are complaint and reported-loss figures, not a measure of every incident.

The same report separately identifies AI-related complaints and records US$30,256,592 in BEC losses among complaints tagged with an AI-related descriptor. That does not mean most BEC is AI-generated, nor does it establish that AI caused each loss. It does show why an organization should not assume a fraudulent communication will look clumsy or obviously false.

Canadian organizations face the same underlying threat. Official RCMP guidance describes the direct-deposit change scheme and stresses two-step verification. BEC totals broadly should never be presented as payroll-diversion totals, but the scale of reported BEC losses shows why identity verification belongs inside financial control.

The HR problem is really an identity problem

When HR receives a direct-deposit request, the organization already knows the employee exists. The question is whether the person making this particular request is authorized to act as that employee.

NIST’s current Digital Identity Guidelines, SP 800-63 Revision 4, cover identity proofing, authentication and federation for users interacting with government systems. The companion SP 800-63A-4 explains that identity proofing is intended to provide useful assurance that an applicant is who they claim to be. These publications are not mandatory payroll procedures for every private employer. Their useful principle is that assurance should be appropriate to the risk of the transaction—not assumed because a communication appears familiar.

For HR, that produces one operational question: which employee changes are consequential enough to require independent verification?

Not every HR change carries the same risk

Changing a preferred name on an internal directory is not necessarily equivalent to changing the bank account that receives salary. Organizations should identify their high-impact changes in advance. Depending on the organization, they may include:

  • direct-deposit, payroll banking or other payment-destination changes;
  • benefits-related financial or beneficiary changes;
  • contact details used for account recovery;
  • requests involving tax or highly sensitive employee records;
  • password or credential recovery;
  • redirection of sensitive documents;
  • privileged-access changes; and
  • changes that could affect later identity verification.

The objective is not to add friction to every HR interaction. It is to identify the smaller set of changes where getting the identity wrong could cause significant harm.

Benchmark framework

Pause Before You Change

Before completing a high-impact employee change, ask five questions.

1. What is actually changing?

Determine whether the request affects money, identity, sensitive employee information, account recovery, benefits or system access. The verification standard should reflect the consequence of an incorrect change.

2. How did the request arrive?

An authenticated portal, corporate email, personal email, text, telephone call, video meeting, manager or help-desk ticket each provides different evidence. No single channel automatically proves identity. A legitimate mailbox can be compromised, a telephone number can be spoofed or taken over, and an attacker may know personal details.

3. Does the request bypass the normal process?

A request to skip a portal, ignore a form, accelerate a change or make an exception deserves scrutiny. Urgency can be genuine, but it should not eliminate an identity control. The more consequential the change, the less willing the organization should be to abandon verification because the request is urgent.

4. Can the employee be verified independently?

Use a channel or information the organization trusted before the new request arrived. The FBI recommends secondary channels or two-factor verification for account-information changes; the RCMP recommends a two-step process and another communication method rather than email alone.

5. Is there a record of the verification?

Document the type of change, how it arrived, the verification procedure, any exception, the approver and the effective time. A repeatable record prevents the standard from changing according to who receives the request.

Out-of-band verification is a small step with a large purpose

Do not verify a high-impact request solely through the communication that delivered it. If payroll receives an email asking to change direct deposit, replying “Please confirm this is you” adds little assurance when the mailbox itself may be compromised.

A stronger process uses an established employee portal, contact information already on file, a known internal directory, or another independently trusted route. If the message says, “I changed my phone number too—call this new number,” using that number is not independent verification.

The Canadian Centre for Cyber Security recommends communicating through an alternate, verified channel to reduce exposure to social engineering and BEC. This is not about treating every employee as suspicious. It is about treating certain transactions as important enough to verify.

What AI changes—and what it does not

Generative AI can help produce polished, contextually appropriate messages, and synthetic audio can make impersonation more persuasive. Public information and data from earlier breaches may add realistic details. A familiar address may also be a genuinely compromised account.

AI raises the quality and accessibility of impersonation. It does not change the basic control. HR employees should not be expected to determine personally whether every email, voice or video is authentic. If a familiar voice requests a high-impact change, follow the verification procedure. If a video looks authentic but asks to bypass normal controls, follow the procedure. If the language is perfect and includes real company context, follow the procedure.

Benchmark’s guide to deepfake job candidates and remote-worker identity risk shows why identity assurance must connect the person interviewed, the employment record, the account user and the payroll destination. The same idea continues throughout the employee lifecycle.

The employee experience matters too

Security controls fail when employees see them as arbitrary obstacles. HR should explain the reason: “For your protection, changes to payroll banking information require independent verification.” That communicates a consistent safeguard, unlike an accusatory response such as, “We do not believe this request is really from you.”

Employees should know in advance where legitimate direct-deposit changes are submitted, whether HR ever requests banking information by email, which verification steps to expect, what HR will not request through an unsecured channel and how to report suspicious payroll or HR communications. Predictability supports trust and gives HR a consistent process.

What if the change has already been made?

Speed matters when payroll diversion is suspected. The organization should follow its incident process and may need to:

  • stop or contain further unauthorized changes;
  • alert payroll, HR, information security, privacy/legal, finance and leadership according to the facts;
  • contact the relevant financial institution promptly when funds may have moved;
  • assess whether an email, HR, payroll or other account was compromised;
  • preserve messages, logs, approvals and transaction records;
  • check whether other employees received similar requests; and
  • evaluate whether privacy, contractual, insurer, regulatory or law-enforcement reporting is implicated.

RCMP guidance directs Canadian organizations to report BEC to IT, local police and the Canadian Anti-Fraud Centre, and to contact the financial institution immediately if funds transferred. FBI guidance similarly tells U.S. victims to contact the originating financial institution promptly and file a detailed complaint with IC3.

A report or recall request does not guarantee recovery. Legal, privacy, cybersecurity and incident-response questions remain fact-specific. Use Benchmark’s Business Email Compromise Response Playbook for the broader response, the employee data breach response-plan guide when personal information may be involved, and the employee-support playbook when an affected person needs a separate support workstream.

Educational boundary: this article describes operational practices and official guidance. It is not individualized legal advice and does not create a universal payroll procedure or notification rule.

Design the process before the suspicious email arrives

The worst time to invent an identity-verification procedure is five hours before payroll closes. Decide in advance which changes are high impact, which require independent verification, what channels are approved, who can authorize exceptions, what happens when verification fails, and who contacts the employee, financial institution and response team.

These are governance questions, not only technical questions. HR, payroll, security, privacy/legal, finance and leadership each own part of the workflow. Benchmark’s workplace AI governance framework provides a connected model for ownership, use-case review, human accountability and lifecycle monitoring. The Shadow AI guide addresses the separate risk of employees placing confidential information into unapproved AI tools.

Practical review

HR and payroll checklist

  • Do we have a documented direct-deposit change process?
  • Can employees make banking changes through an authenticated system?
  • If a request arrives by email, do we verify it independently?
  • Do we use contact information already on file rather than details in the request?
  • Can HR and payroll pause an unusual request without penalty?
  • Do employees know how legitimate payroll changes are made?
  • Do employees know how to report suspicious HR communications?
  • Have we identified other high-impact employee changes?
  • Does the process account for compromised real email accounts?
  • Does training avoid relying on grammar, voice or visual appearance as proof?
  • Do staff know the internal fraud-escalation route?
  • Can the organization contact its financial institution quickly?
  • Have HR, payroll, IT/security and privacy teams tested the procedure together?

Unclear answers are not a reason for blame. They identify an opportunity to strengthen the process before a real impersonation attempt tests it.

The bigger lesson for HR

The boundary between cybersecurity and HR is becoming harder to draw. Security protects email; IT manages authentication; finance controls money; payroll processes compensation; HR maintains employee records; privacy teams oversee personal-data handling. An attacker looks for the point where trust can be converted into action—and sometimes that point is an HR inbox.

The strongest question may no longer be, “Did this request come from the employee’s email?” It may be, “Before we make this change, how do we know we are dealing with the employee?” That short pause can turn an ordinary administrative workflow into an important organizational control.

Sources and official guidance

Primary government sources reviewed for this article are listed below. Organizations should confirm current guidance and requirements for their circumstances.

Continue with Benchmark

Prepare before an incident forces the conversation.

Workplace risk increasingly crosses HR, payroll, privacy, cybersecurity and employee support. Explore practical resources for organizational leaders, then use the existing Knowledge Center subscription form for future professional guidance.

Explore and subscribe in the Knowledge Center