Compromised email and SSO accounts give attackers a path to both identity and workflow abuse. Once inside, they can read payroll documentation, reset access, hide alerts with inbox rules, and change direct deposit details. The risk is not only unauthorized login, but the attacker’s ability to manipulate trusted business processes that employees and finance teams rely on.
Why these frauds succeed after one account compromise
Payroll fraud usually succeeds because the attacker is not starting from scratch, they are inheriting a trusted position inside an existing business process. A compromised mailbox or identity provider session can reveal who approves changes, what the normal wording looks like, and which systems or helpdesks can be influenced without raising immediate suspicion. In other words, the compromise gives both visibility and cover.
That matters because payroll and direct deposit workflows are built around legitimate exceptions, not just technical access. A user can normally request account updates, HR can process changes, and finance may rely on email confirmations or shared portal access. Once an attacker controls the account that anchors those communications, they can imitate the expected sequence and steer the process toward fraudulent destination accounts.
The strongest Ultimate Guide to NHIs reference point here is not the non-human framing itself, but the broader identity lesson: when trusted credentials are overprivileged or poorly governed, the compromise often expands from login access into business-process abuse. That same dynamic appears in email takeover, where the account becomes a control plane for requests, approvals, and exceptions.
What attackers actually exploit inside payroll and direct deposit workflows
Once inside, attackers tend to use a small set of repeatable actions. They may search for payroll calendars, prior direct deposit notices, manager names, or HR service contacts. They may create inbox rules to hide challenge messages, approval notices, or out-of-band alerts. They may also use the compromised account to reset other credentials or to answer follow-up questions in a way that keeps the fraud moving forward.
direct deposit fraud is especially effective when the change process depends on email alone, or when the receiving bank account change is treated as a routine administrative request. If the fraud path includes a self-service portal, attackers often look for weak identity recovery, stale sessions, or insufficient step-up checks before a payout destination can be altered.
Incidents involving compromised credentials and unauthorized access show the same pattern: once trust is attached to the account, the attacker can move from initial access to secondary actions that look operationally normal. A useful reference is The 52 NHI breaches Report, which illustrates how credential compromise often turns into lateral abuse of trusted workflows rather than a single isolated login event. For email-centric abuse, the Internet Archive breach and Cisco Active Directory credentials breach are also useful examples of how exposed authentication material can lead to broader account and access abuse.
Risk and Threat Considerations
Payroll fraud is attractive because it converts a single identity compromise into direct financial loss with relatively low noise. The attacker is not trying to defeat every control, they are trying to exploit the fact that many organisations still trust email, portal updates, and internal approval chains as evidence of legitimacy. That makes mailbox control, session persistence, and inbox filtering especially dangerous when they sit upstream of payment changes.
Failure mechanism: The attacker uses the compromised account to intercept or forge the communication path that payroll and finance rely on, then redirects the payment destination before the victim or reviewer notices the change.
Impact: The organisation can lose funds, suffer recovery and dispute costs, and expose employees to wage diversion, while also discovering that its account recovery and approval process was too easy to spoof.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Payroll fraud often follows credential compromise and secret misuse. |
| NHI-03 — Privilege and Access Governance | Abuse becomes easier when an account can change payment or approval paths. | |
| NHI-06 — Visibility and Detection | Hidden inbox rules and silent changes are common in account takeover fraud. | |
| Recommendation — Rotate exposed credentials and remove any account secrets that can alter payroll workflows. Review and restrict any account that can approve or redirect payroll changes. Monitor for mailbox rule creation, forwarding changes, and unusual payroll-related access. | ||
| CIS Controls v8 | 5 — Account Management | Compromised accounts are the entry point for payroll and direct deposit abuse. |
| 6 — Access Control Management | Least privilege limits who can change payment destinations or approvals. | |
| 8 — Audit Log Management | Fraud often leaves traces in mailbox rules, resets, and payout edits. | |
| Recommendation — Harden account lifecycle controls and disable dormant access paths quickly. Limit who can alter payroll records and require stronger checks for exceptions. Log and review identity and payroll change events for anomalous patterns. | ||
| MITRE ATT&CK | T1114 — Email Collection | Attackers often read payroll emails and change notices to guide fraud. |
| T1098 — Account Manipulation | Fraudsters commonly alter settings, rules, or recovery paths after compromise. | |
| Recommendation — Hunt for mailbox access that targets payroll and benefits communications. Detect unauthorized mailbox, recovery, and account-setting changes quickly. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Strong identity controls reduce the chance that one compromise reaches payroll actions. |
| Recommendation — Enforce stronger authentication and access checks for financial workflow changes. | ||
Practitioner Guidance
What to verify: Treat any mailbox or SSO compromise as a workflow-integrity incident, not just an access incident. Verify whether payroll change requests, bank-detail updates, MFA resets, or delegated inbox rules were modified in the same window as the compromise.
Decision rule: If the account can influence payroll, HR, or finance communications, prioritize containment of the business process first, then credential reset and session revocation. Waiting to confirm fraud before freezing the change path gives the attacker time to complete a one-time payout diversion.
Practitioner takeaway: The key control question is not whether the attacker logged in, but whether they gained enough trusted position to make a payment instruction look normal to the people and systems that approve it.