Payroll email: scam or real?

If an email asks you to change bank details, confirm IBAN/routing, or “re-verify” direct deposit — verify in a known HR/payroll system first.

What to do now (safe route)

Rule: Don’t reply. Don’t click. Don’t send bank details or codes by email. Verify via a known HR/payroll portal or official internal channel.

Route A — The request exists in the portal

  • Do the change only inside the portal.
  • Confirm with a second internal channel (Teams/Slack call, or directory number).
  • Save evidence (ticket ID / confirmation screen).
  • Check the next payday deposit.

Why: email links and signatures are easy to spoof; portal workflows are harder to fake.

Route B — The request does NOT exist

  • Assume scam and stop interacting.
  • Report to IT/Security (use “Report phishing” if available).
  • Tell Payroll/HR (via known channel) that a diversion attempt is circulating.
  • Secure your payroll account (password reset + MFA if available).

Why: payroll diversion often targets multiple employees at once.

Report to IT/Security (copy-ready text) Payday soon / already shared details?
Copy-ready report text (open)
Subject: Suspicious payroll email / possible direct deposit diversion attempt

Hi IT/Security team,

I received a payroll/HR email asking for a bank detail or direct deposit change.
I did NOT complete any change via the email.

Please investigate and advise next steps:
- Sender / display name:
- From address:
- Date/time received:
- Email subject:
- Any links/attachments mentioned:
- I verified in the HR/payroll portal: (Yes/No)
- If available: I used the “Report phishing” button (Yes/No)

Request: Please check whether this is phishing or a compromised mailbox and confirm whether any payroll system access was attempted.

Thanks,
[Your name]
        

Common patterns

  • “Urgent: update direct deposit today.”
  • “We migrated payroll systems — confirm your bank details.”
  • “Payroll will be delayed unless you verify.”
  • “Download this form and reply with bank details.”
  • “Scan this QR to verify payroll.”
  • “Send ID documents for payroll setup.”

Red flags

  • Asks for bank details by replying to the email.
  • Asks for OTP/MFA codes (always scam).
  • Pressure: “today”, “final notice”, “pay will fail”.
  • Link to a non-company domain or shortened URL.
  • Unexpected attachment (PDF/ZIP/Office document).
  • Request bypasses normal HR workflow (“just email me your details”).

How to verify safely

  1. Open the HR/payroll portal from a bookmark (not from the email).
  2. Look for the same request/task/ticket in the portal.
  3. Verify the sender using the company directory / intranet HR page — not the email signature.
  4. Only apply changes through the portal workflow.
  5. Secure access: change password + enable MFA if available.
  6. Report internally: use “Report phishing” if available; otherwise forward per policy (often as attachment).
If you clicked or entered details: contact Payroll/HR via a known channel and ask them to lock direct deposit changes.

If payday is soon or pay was diverted

Priority order: 1) Payroll/HR lock direct deposit changes • 2) Request audit trail • 3) Notify your bank if needed • 4) Follow company incident process.
  • Contact Payroll/HR via a known channel (directory number / internal ticket), not via the email thread.
  • Ask them to freeze/lock direct deposit changes until verified.
  • Ask for an audit trail/change log for your profile and deposit settings.
  • If money already moved: ask payroll what reversal process exists; notify your bank if your account details were exposed.

If payday is close, act first — analyze later.

Risk levels

Low

Verified in portal + confirmed via known channel. Default action: proceed only in the portal.

Medium

Looks internal, but asks for confirmation outside the portal. Default action: verify in portal + confirm via directory channel.

High

Asks for bank details/codes, urgent action, QR, or attachments. Default action: assume scam, report, and lock changes if payday is near.

FAQ

Can HR ever ask for bank details by email?

Some companies do, but it’s a risky pattern. Safe rule: only change bank details inside the HR/payroll portal or verified internal workflow.

What if I already shared my IBAN/routing or clicked the link?

Treat it like an incident: contact Payroll/HR via a known channel to lock direct deposit changes, reset payroll portal credentials, enable MFA if available, and report to IT/Security.

What if my pay was diverted?

Contact Payroll immediately to lock changes and request an audit trail. Notify your bank if needed and follow your company incident process so the timeline is documented.

The sender looks like our HR address. Does that mean it’s real?

No. Display names can be spoofed and real mailboxes can be compromised. Verify via portal + directory channel, not the email signature.

The email says payroll will be delayed unless I act today. What should I do?

That pressure is a common scam trigger. Don’t act from the email. Open the HR/payroll portal from a bookmark and verify, then confirm via an internal channel.

Should I forward the email to IT/Security?

Yes. Use your company’s “Report phishing” button if available. Otherwise forward per policy (often as an attachment to preserve headers).

Is this the same as a bank scam email?

Similar mechanics, different target: your payroll destination. If it’s framed as a bank security alert, start with your bank-email route, then verify payroll in the portal.

How do I verify the sender independently?

Use the company directory or intranet HR page and contact via known internal channels. Don’t use phone numbers or links from the email signature.

ClearExplained — simple pages that remove panic and reduce mistakes.