Please update my bank details before Friday
An email arrives: 'Hi, I've changed banks, please pay my wages into the new account from this month', with account details. It comes from an address with the employee's name, or from what looks like the client's HR manager. It is pay week. The administrator updates the record so the employee does not miss out.
On pay day, the real employee rings the client: they have not been paid. The email was not from them. The money has gone to an account that will be empty by the afternoon.
Why bureaus are a target
Payroll diversion is a well-known fraud because it is simple: one email, one change, one pay day. A bureau handles many employees for many clients, and the administrators do not know most of them personally, so they cannot recognise a voice or a writing style. Email addresses are easy to fake or to register in someone's name.
The pressure of pay week helps the fraudster. The request usually arrives close to the cut-off, with a gentle urgency that discourages checking.
What a diverted wage costs
The employee is left without pay, and someone, the client or the bureau, often has to make them whole while the fraud is investigated. Recovery from the fraudster's account is uncertain. The client's trust in the bureau takes a knock, and depending on the facts, questions about who was responsible can get difficult. None of this is prevented by staff being careful in general; it needs a routine that does not depend on spotting a fake.
| Request arrives by | Risk | Verification route |
|---|---|---|
| Email from the employee's name | Easily faked | Confirm through the portal or a known number |
| Email from the client's HR contact | Their mailbox may be compromised | Callback to a number already on file |
| Phone call | Caller may not be who they say | Code to the phone number on record |
| Employee portal, logged in | Lower, if login is strong | Notification to the old contact details |
How we build a bank change routine
- Bank detail changes are accepted only through set routes, such as the employee portal or a secure change form, and emails asking for a change get an automatic reply pointing to that route.
- Every change request goes into a holding state and is not applied until verified.
- Verification uses contact details already held, never details in the request itself: a code to the mobile number on file, a confirmation in the portal, or a callback to the client on a known number.
- Once verified, the change is prepared for import into your payroll software with the administrator's approval.
- The employee is notified at their existing contact details that their bank details changed, so a fraudulent change is spotted by the real employee quickly.
- Requests close to the cut-off follow the same rule. If verification cannot happen in time, the employee is paid to the existing account and the change applies next period, a rule agreed with each client in advance.
Supplier-style checks of account names against bank records can be added where your bank or a provider offers them. They reduce the risk; no routine removes it completely.
A change that cannot be rushed through
Administrators no longer have to judge whether an email is genuine; the routine does not rely on it. Fraudsters who rely on urgency find the route closed. Genuine employees get a quick, simple way to change their details. And the client can see that the bureau has a clear, written rule for one of the most common payroll frauds.
Is your bureau exposed?
- Bank detail changes are accepted by email.
- Administrators update details in pay week to avoid delays.
- There is no step to verify a change outside email.
- Employees are not told when their bank details change.
- Clients have not agreed a rule for late change requests.