When attackers alter direct deposit details, the next paycheck can be redirected to an account they control. That creates immediate financial loss, employee disruption, and a recovery burden for payroll, HR, and security teams. The impact is often worse for smaller organisations with less financial slack and fewer response resources.
What Compromised Deposit Changes Enable
A compromised identity turns payroll details into a high-value financial control, not just a data field. Once an attacker can change direct deposit instructions, they can redirect the next payment stream, create confusion over whether the change was legitimate, and force the organisation to prove which identity made the modification and when.
The key issue is that direct deposit changes often sit inside an approved business workflow, so the act itself may not look anomalous. That is why organisations should treat this as an identity-driven payment redirection problem, not only a payroll fraud event. If the account used to make the change was overprivileged or poorly monitored, the blast radius expands quickly. For identity context and control patterns, the Ultimate Guide to NHIs is useful because it covers governance, lifecycle, visibility, and least privilege across account types that can be abused to alter records.
One widely cited signal from NHIMG’s Ultimate Guide to NHIs is that 97% of NHIs carry excessive privileges, which is a reminder that overbroad access makes simple record changes much harder to contain when an account is compromised.
Why the Impact Extends Beyond the Missed Paycheck
The immediate loss is often the redirection of salary to an account the attacker controls, but the operational damage usually continues after the transfer. Payroll teams may need to reverse or reissue payments, HR may need to validate employee identity and ownership claims, and security teams may need to determine whether the same identity was used elsewhere for fraud, data access, or lateral movement.
This is also a trust problem. Employees expect payroll records to be stable, and even a short-lived compromise can trigger concern about broader account safety, data exposure, and internal control weakness. If the attacker changed bank details using a legitimate session or a stolen credential set, the investigation must focus on access provenance, not only on the beneficiary account. Case-based incident analysis in 52 NHI Breaches Analysis is useful for understanding how compromised access is turned into downstream abuse.
When an identity is the path into a payroll workflow, the real cost is usually measured in recovery time, exception handling, and confidence loss. Smaller organisations often feel that burden most sharply because a single fraud case can consume the same people who also have to restore service, notify stakeholders, and harden controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Direct deposit changes depend on restricting who can alter payroll records. |
| 8 — Audit Log Management | You need traceability for who changed bank details and from which account or session. | |
| Recommendation — Limit payroll record changes to authorized roles and review those entitlements regularly. Log and review payroll profile changes with user, time, device, and source context. | ||
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication, and Access Control | Compromised identities are the enabling condition for payroll redirection fraud. |
| DE.CM — Security Continuous Monitoring | Monitoring is needed to detect unusual deposit edits and account misuse quickly. | |
| RS.MI — Incident Mitigation | A compromised deposit change requires fast containment and correction. | |
| Recommendation — Strengthen authentication and access control for payroll and employee self-service systems. Monitor payroll-change events for anomalous identity, device, and location patterns. Contain the affected account and reverse the fraudulent payment path immediately. | ||
| MITRE ATT&CK | T1098 — Account Manipulation | Attackers often change account-linked settings to maintain access or redirect outcomes. |
| T1078 — Valid Accounts | The attack depends on abuse of a legitimate identity to make trusted changes. | |
| Recommendation — Hunt for unauthorized account-setting changes and related persistence activity. Investigate legitimate-account abuse rather than assuming the change was externally obvious. | ||
Practitioner Guidance
What to prioritise: Treat any direct deposit change made from a newly used device, unusual location, or recently compromised account as a fraud incident first and a payroll ticket second. The decision point is whether the change can be independently attributed to the employee before the next payroll cycle closes.
What to verify: Confirm whether the modifying identity had standing access to employee self-service changes, whether the request was subject to step-up verification, and whether the bank-account change triggered a separate out-of-band approval path. If none of those checks exist, the control failure is likely systemic, not isolated.
Common mistake: Relying on account password resets alone after the event. That may stop reuse of one credential, but it does not address whether payroll records, session tokens, mailbox access, or approval workflows were already abused.
Practitioner takeaway: The important judgement is not just how the money moved, but whether your payroll change process can prove legitimacy fast enough to stop the next payment from being misdirected.
Related resources from NHI Mgmt Group
- What happens when attackers use compromised identity or access paths to move from initial access to deeper compromise?
- What happens when attackers use compromised email accounts and university identities to target recruitment teams?
- What happens when attackers use compromised credentials to combine exfiltration with encryption in a breach?
- What happens when attackers use compromised credentials to target municipal databases without strong segmentation or monitoring?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org