All insights

Wire fraud

The direct deposit change that should stop the batch

Published
September 26, 2026
Read
4 min
Desk
Coffr Content Desk

The file can balance, the funding can clear, and the wrong account can still receive the wages.

A payroll batch approval screen paused on a new direct deposit routing change before release.

The payroll run is balanced. The approval window is closing. Then a direct deposit change arrives from an employee, a contractor, or a client administrator who says the new account has to be used this cycle.

That is the moment payroll diversion fraud moves from message to money movement. The fraud is not hidden in the batch totals. It sits in the instruction change that enters just before release.

For a payroll provider, the risk is sharper than it looks. One provider may process wages for many employers, across different payroll calendars, approvers, and bank rules. One weak routing change can take a worker's pay, pull the employer into urgent calls, and put the payroll manager under a review that feels personal even when the attack began somewhere else.

The batch can be right and still wrong

Payroll diversion fraud is a payment instruction failure. The wage calculation may be correct. The employee record may be real. The employer may be legitimate. The fraudster only needs to replace the destination account before funds move.

That distinction matters for payroll providers. Many controls are built around payroll accuracy, tax treatment, funding sufficiency, approval timing, and file transmission. Those controls matter. They do not always prove that a changed bank account belongs to the person it claims to serve.

The criminal does not need to break the payroll system in a dramatic way. A new hire submits banking information. An employee says they changed banks. A client administrator uploads an updated file. A contractor asks to split pay differently. A busy team sees normal work under a deadline.

The batch did what it was told. That is the problem.

The change is the control point

The risky sequence often begins outside the provider's core workflow. A mailbox is compromised. Credentials are phished. A worker is impersonated. A client side administrator is coached into making the change. The attacker gathers enough context to sound ordinary.

Then the instruction arrives through email, a support ticket, an employee portal, a spreadsheet upload, or an HRIS integration. It may include a bank name, routing number, account number, direct deposit form, or image that looks familiar enough to pass a hurried review.

The timing is the tell. Payroll has hard dates. People notice missed wages fast. Payroll teams are trained to protect the pay date, and that professional instinct can be turned against them.

A last minute bank change should not be treated as clerical maintenance. It is a request to route money to a new destination.

Signals worth stopping for

A good pre release gate does not need certainty. It needs enough doubt to pause the instruction before funds leave.

Several signals deserve attention before release:

  • A bank account or routing change inside the payroll cutoff window.
  • A change submitted from a new device, location, administrator, or contact channel.
  • A mismatch between the account holder and the worker or payee identity.
  • A change that follows a password reset, MFA reset, email change, or phone change.
  • A new account used across multiple workers, employers, or entities.
  • A change to an institution or account type that differs from the worker's prior pattern.
  • A batch with many routing changes that arrived through upload rather than worker level confirmation.

No single signal proves fraud. The point is to make the changed destination visible to the person who can stop release.

What a payroll protection POC should prove

A payroll protection POC should test one narrow claim. Can the provider identify risky routing changes before release and create evidence that a payroll lead, CFO, client, bank, or auditor can understand afterward.

Start with a change freeze. Treat direct deposit changes inside the freeze as exceptions. Exceptions should require documented verification, not informal approval in a chat or email.

Then separate identity confidence from account ownership confidence. A valid login may show that someone entered a portal. It does not always prove the destination account belongs to the intended payee. The review should show what was checked, what was not checked, and why the file was allowed to move.

Approval also needs better evidence. A second approver may look at the payroll total, the client funding status, and the release date. If that approver cannot see the account change history, dual approval becomes a review of the wrong evidence.

Give payroll staff a safe stop path. If a callback fails, if the account relationship is unclear, or if a last minute change carries too many risk signals, the team needs permission to delay the change without being punished for protecting the file.

For your own release process, the hard test is simple. A changed destination inside the cutoff should be treated as money movement, not maintenance. If the evidence is thin, the batch waits.

Questions practitioners ask

What is payroll diversion fraud?

Payroll diversion fraud occurs when wages are redirected to an account the intended worker does not control. In payroll operations, it often appears as a direct deposit change or routing update shortly before release.

Why are last minute routing changes risky?

They arrive when payroll teams are under pressure to protect the pay date. That pressure can shorten verification, especially when the request appears to come from a known employee, client administrator, or established channel.

Does identity verification stop payroll diversion fraud?

It helps, but it is not enough on its own. A valid login or known email thread does not always prove that the destination bank account belongs to the intended payee.

Where should a payroll provider place the control?

The control should sit before release, where a new or changed bank account is allowed into a funded batch. The approver should see the change history, risk signals, and verification evidence before the file moves.

Share and cite

XLinkedInRedditEmail

Community newsletter

The Trust Layer Briefing

CFOs, controllers, and AP leaders subscribe for weekly research on BEC vectors, ERP gaps, and payment instruction security.

One email each Thursday. No spam, one-click unsubscribe.

Practitioners can also request a seat on The Coffr Research Panel.