Join our Newsletter — 33% off our NHI Course

What are the signs that an employee’s payroll account or email account is being abused for fraud?

Common warning signs include unfamiliar inbox rules, especially short or repetitive names, email filters tied to payroll or Workday, multiple Okta sessions from unusual operating systems, and repeated MFA push prompts. Employees should also watch for incorrect pay distribution, unexpected lockouts, or bank account changes. Any one of these signals warrants immediate review.

How payroll and mailbox abuse usually shows up before the fraud is obvious

The earliest indicators are usually small changes in account behaviour rather than a single dramatic event. Unfamiliar inbox rules, payroll-related filters, repeated MFA prompts, and unusual session patterns often appear before a pay diversion or mailbox forwarding event is discovered. The key signal is inconsistency with the employee’s normal workflow, especially when the activity clusters around payroll, HR, or finance systems.

Mailbox abuse often starts with persistence, not theft. Attackers try to stay invisible by creating rules that move messages, hide security notices, or redirect payroll confirmations, while account abuse shows up as repeated logins from strange operating systems or locations. When those signs appear together, the account should be treated as actively manipulated until proven otherwise.

Identity and access lifecycle controls matter here because payroll fraud often succeeds only after an account has been altered enough to keep the attacker inside.

Fraud patterns that point to payroll or email compromise

Not every warning sign means the account is fully taken over, but some patterns are especially persuasive. A changed bank account, a new direct-deposit destination, or pay distribution that no longer matches the employee’s normal instructions is a strong payroll fraud indicator. On the email side, short or repetitive inbox rule names, filters tied to payroll or Workday, and hidden messages about password resets or payment changes usually mean the mailbox is being used to support a longer fraud chain.

Repeated MFA push prompts are important because they often indicate an attacker is testing approval fatigue or waiting for a mistaken tap. Multiple Okta sessions from unusual operating systems suggest the account may be in use on a second device, which is consistent with session theft, token abuse, or concurrent attacker access. Unexpected lockouts can be a side effect of the attacker changing recovery details, triggering security controls, or racing the real user for control of the account.

For a concrete fraud pattern, the Microsoft Midnight Blizzard breach shows how weak account controls and legacy access can be abused to stay inside an environment long enough to pursue follow-on compromise.

Risk and Threat Considerations

Payroll and email compromise are high-value because they combine access, trust, and timing. The fraud can be limited to one payment cycle, or it can become a broader business email compromise path where attackers use the mailbox to approve changes, conceal notifications, and redirect employees or vendors.

Failure mechanism: The attacker gains mailbox or payroll access, creates persistence through rules, filters, or session abuse, then uses trusted communications to change payment instructions or suppress alerts until the fraudulent action is completed.

Impact: The organisation can lose wages or funds, miss the window to reverse the transfer, and expose additional sensitive records because the same account often carries payroll notices, HR correspondence, and security alerts.

Payroll compromise patterns are closely related to broader credential abuse cases such as the Poland Military Breach, where email credential compromise created access to sensitive communications, and the MailChimp Breach, where social engineering of employee credentials enabled wider downstream exposure.

Practitioner Guidance

What to verify: Check whether the mailbox has new forwarding or filtering rules, whether those rules target payroll, HR, or security messages, and whether the payroll system shows a recent bank or routing change that the employee cannot confirm. Review session history for unfamiliar operating systems or concurrent logins, because that often separates a nuisance alert from an active compromise.

Escalation / exception: Treat any one of the listed indicators as sufficient to freeze risky payment changes and force identity revalidation before the next payroll run. If repeated MFA prompts are present, assume the attacker may still be attempting access and prioritise credential reset, rule removal, and session revocation over routine helpdesk troubleshooting.

Practitioner takeaway: In payroll fraud, the most useful mindset is to look for control of the communication path as well as control of the account, because attackers usually need both to make the change and keep the victim from noticing it in time.