TL;DR: University payroll and refund fraud succeeds when stolen credentials are treated as proof of ownership, allowing attackers to reroute deposits through self-service portals, according to 1Kosmos. The real failure is not payment processing, but identity verification at the moment sensitive account changes occur.
At a glance
What this is: This is an analysis of direct deposit fraud in higher education showing that credential theft becomes payout diversion when campus systems treat password knowledge as proof of account ownership.
Why it matters: It matters because IAM, IGA, and fraud teams need stronger identity verification at sensitive account-change points, not just login controls, to stop payment redirection after credential compromise.
Context
Direct deposit fraud is a campus identity governance problem, not a payments problem. When self-service portals let people change bank details with only password-based login, the organisation is trusting authentication as proof of ownership, which credential theft can defeat.
Universities face a large and fragmented identity surface because students, faculty, staff, and temporary workers move through multiple systems with inconsistent verification points. That makes payout redirection possible even when the login itself appears legitimate.
The pattern is typical of environments that separate payroll, bursar, and HR controls. The weakness is not the transaction itself, but the absence of step-up identity proofing at the moment a sensitive account change is requested.
Key questions
Q: What breaks when universities trust password login for direct deposit changes?
A: Password login breaks as a control when it is treated as proof of payroll ownership. A stolen credential can authenticate a fraudster into the self-service portal, where the attacker changes bank details and waits for the next payment cycle. The failure is at the change point, where identity proofing should confirm who is requesting the update.
Q: Why does direct deposit fraud create more than a payments problem?
A: Because the fraud begins as an identity failure and ends as financial loss. When the institution lets a bank-account change proceed without verifying the person and the destination account, it turns authentication into a transfer mechanism. That creates replacement-payroll costs, investigation burden, and reputational harm alongside the stolen funds.
Q: How can security teams tell whether account-change controls are strong enough?
A: Look for whether sensitive changes require more than a valid session. If bank detail updates, payment rerouting, or similar high-impact actions can be completed with only a password and no step-up verification, the control is too weak. A strong workflow creates a separate trust decision at the moment of change.
Q: Should identity teams treat self-service payroll updates as high-risk workflows?
A: Yes. Any workflow that can redirect money should be governed as a high-risk identity event, not a convenience feature. That means separate verification, destination-account validation, and risk-based escalation. The same logic applies to payroll, stipends, tuition refunds, and financial-aid disbursements whenever account ownership can be changed online.
Technical breakdown
Why password-only trust fails in payout workflows
Password knowledge proves only that someone holds an authentication factor, not that they are the rightful owner of a payroll or refund destination. In campus environments, that distinction matters because direct deposit changes create immediate financial impact while often leaving few security signals. Once an attacker authenticates with stolen credentials, the portal may treat the request as legitimate and permit a bank-account update without additional identity proofing. That is a governance failure at the point of change, not a malware problem. The real weakness is the assumption that successful sign-in equals authorised account control.
Practical implication: require stronger identity proofing than login alone before approving bank detail changes.
How self-service portals become fraud accelerators
Self-service is efficient when the user is already trusted, but it becomes risky when it is used as the sole control over sensitive financial changes. Direct deposit updates are particularly attractive because the attacker only needs one successful change before waiting for the next payroll or refund cycle. If the institution does not bind the change request to the verified person and the verified account, the portal simply becomes a transfer mechanism for stolen wages. This is why account-management workflows need their own control points, separate from everyday access.
Practical implication: place step-up checks inside the change workflow, not just at initial login.
Why account ownership verification matters more than device trust
Device reputation and location checks can help, but they do not answer the core question: does the bank account belong to the authenticated person? That is why account-ownership verification is a distinct control layer in direct deposit fraud prevention. A mule account can still be used from a familiar device if the credential was stolen. The stronger model combines identity proofing with account validation so the institution verifies both the requester and the destination account before the change is accepted. In higher education, that closes the gap between access and entitlement.
Practical implication: validate account ownership before any payroll or refund destination is updated.
Threat narrative
Attacker objective: The attacker wants to divert payroll, stipends, or refunds into accounts they control without triggering immediate detection.
- Entry begins when attackers obtain campus credentials through phishing or stolen logins and use them to access payroll or self-service portals.
- Escalation occurs when the authenticated session is used to change direct deposit details without stronger verification of the requestor or destination account.
- Impact follows at the next payday or refund cycle, when legitimate funds are redirected to a mule account and the fraud is only discovered after payment has cleared.
Breaches seen in the wild
- Hugging Face Spaces breach 2024: Unauthorised access to Hugging Face Spaces may have exposed secrets users stored for AI apps; tokens were revoked and org tokens removed.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Credential possession is being mistaken for account ownership: That assumption was tolerable when passwords were harder to steal and account changes were less exposed. In campus payroll and refund workflows, it fails because a valid login no longer proves that the person requesting the change controls the destination account. The implication is that identity assurance must move from authentication alone to change-time verification.
Campus finance workflows create an identity trust gap at the moment of highest consequence: Universities often protect logins better than they protect sensitive entitlement changes. That is backwards for direct deposit fraud, where the breach value appears only after the account update is accepted. The practitioner lesson is that access control and payment integrity are no longer separable in these workflows.
Self-service portals are governance surfaces, not just convenience layers: When they govern payroll, stipends, refunds, and bank details, they become identity-sensitive transaction systems. If those systems do not verify the person and the destination account, they effectively delegate payout control to whoever can authenticate. The conclusion is that self-service must be treated as a controlled financial-change process.
Direct deposit fraud exposes an identity blast radius problem in higher education: one stolen credential can affect payroll, student aid, and research stipends across disconnected systems. That makes the blast radius larger than the initial compromise and turns one weak verification point into an institution-wide fraud path. Practitioners should read this as a sign that account-change governance is now part of financial resilience.
Step-up proofing at change time is the named control gap this pattern exposes: The article's central failure mode is not weak payroll processing, but the absence of stronger verification when account data changes. That gap is specific, repeatable, and preventable only if institutions stop treating authentication as the final trust decision. The takeaway is to govern the change event, not just the session.
What this signals
Identity blast radius is the central campus risk: one stolen credential can reach payroll, student aid, and refund workflows if those systems share weak change-time verification. Security teams should map where a single authenticated session can alter money movement, then tighten the controls around those specific actions.
Account-change governance now sits inside identity assurance: institutions cannot rely on login strength alone when the valuable event is the bank-detail update itself. The practical shift is to verify the person, verify the destination account, and treat the change workflow as a privileged transaction.
Campus self-service needs stronger trust boundaries: if routine portal access can alter direct deposit instructions, the institution has allowed convenience to outrun assurance. That pattern should trigger a review of which transactions require step-up proofing before approval.
For practitioners
- Implement step-up verification for bank-detail changes Require additional identity checks such as government ID scan, selfie match, or biometric re-authentication before any direct deposit update is accepted.
- Bind payout changes to verified account ownership Confirm that the bank account belongs to the authenticated user before approving payroll or refund destination changes, so a mule account cannot be substituted after login.
- Add risk-based controls to high-impact account updates Trigger stronger review when a change request comes from a new device, unusual location, or other abnormal pattern that increases the likelihood of credential abuse.
- Separate change governance from routine access Treat payroll and refund updates as sensitive entitlement changes with their own approval and verification path rather than relying on ordinary portal access.
Key takeaways
- Direct deposit fraud on campus is an identity trust failure, not a payment-processing failure, because stolen credentials can be used to reroute legitimate funds.
- The article shows that self-service portals and disconnected campus systems expand the blast radius from one compromised account to payroll, stipends, and refunds.
- Universities can reduce the risk by verifying the person and the destination account at the moment a payment-routing change is requested.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Passwords alone are treated as proof of ownership in the campus fraud pattern. |
| NHI-10 — Human Use of NHI | The attack abuses legitimate user identities through self-service workflows tied to money movement. | |
| Recommendation — Add step-up verification when a user requests a high-risk payout change. Separate ordinary login from sensitive financial-change authorisation. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Students and external campus users fit the identity-proofing problem described here. |
| Recommendation — Apply stronger identity proofing before allowing payment-routing changes. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Direct deposit updates are entitlement changes that should not rely on login alone. |
| Recommendation — Govern bank-detail changes as entitlement updates, not routine account activity. | ||
Key terms
- Direct Deposit Fraud: A form of account takeover where an attacker changes the destination of salary, stipend, or refund payments to an account they control. The fraud succeeds by abusing trusted self-service workflows and weak identity verification at the moment of change.
- Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
- Account Ownership: The assignment of a responsible person or team to an identity or credential. Ownership makes review, escalation, and remediation possible because someone is accountable for why the access exists, whether it is still needed, and what happens when risk is found.
- Sensitive Account Change: A sensitive account change is any update that can alter a person's financial, access, or recovery state, such as payroll routing or bank details. These changes deserve stronger controls than ordinary profile updates because the business impact occurs immediately if the change is abused.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org