Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What should organizations do when a BEC-style request…
Cyber Security

What should organizations do when a BEC-style request targets payroll or direct deposit changes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

Organizations should treat payroll and direct deposit changes as high risk transactions that require step up verification. The best practice is to separate request, approval, and execution duties, then confirm any change through a known internal contact path. Because attackers often exploit human capital management systems, organizations need controls that do not rely on email alone.

Why payroll and direct deposit changes deserve special handling

Payroll change requests are a classic BEC target because they combine urgency, trust, and financial impact. A single successful change can redirect wages, create employee harm, and force costly recovery work. Treating the request as routine creates a gap between the attacker’s social engineering and the organization’s actual control over payment instructions.

The control issue is not just whether the request looks authentic. It is whether the business can prove the requester, separate approval from execution, and preserve a verifiable record of the change. That is why payroll, benefits, and HR workflows need stronger verification than ordinary service requests.

Where the request touches payment instructions, the safest assumption is that email may be the attacker’s starting point, not the source of truth. Use a known internal contact path, not the address or phone number in the message, to confirm intent before any update is made.

How to structure verification so one compromised inbox is not enough

Step-up verification should be built into the workflow, not improvised during an incident. A practical pattern is request, approval, and execution by different people or functions, with the approver using an out-of-band confirmation channel that is already on file. That makes the fraud path longer and gives defenders a second chance to spot inconsistency.

For the change itself, require checks that align with the risk of the transaction: identity proof of the requester, confirmation of the employee’s known contact method, and a short delay or hold for high-impact changes where the business can tolerate it. If the process only validates the message thread, it is still vulnerable to mailbox compromise and impersonation.

Organizations should also be explicit about which systems are in scope. Payroll platforms, HR systems, and any downstream direct deposit processors need the same control logic, because the attacker only needs one weak handoff to succeed.

Risk and Threat Considerations

Payroll redirection attacks are dangerous because they exploit trust in routine financial administration, and the consequence can extend beyond a single fraudulent transfer. Even when the change is detected quickly, remediation often involves employee relations issues, bank coordination, and audit reconstruction.

Failure mechanism: The attacker uses a spoofed or compromised email account to submit a seemingly legitimate change request, then relies on weak approval routing, shared inboxes, or undocumented phone verification to get the update executed.

Impact: Wages can be redirected to an attacker-controlled account, direct deposits can be disrupted, and the organization may face delayed pay, manual reversals, control failures, and reputational damage.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementPayroll changes need strong approval and execution separation.
Recommendation — Enforce least privilege and separate approval from execution for direct deposit changes.
NIST CSF 2.0PR.AC — Access ControlThe request needs verified access decisions and stronger transaction authorization.
GV.OC — Organizational ContextPayroll fraud handling depends on assigning ownership and escalation paths.
Recommendation — Require verified access decisions before any payroll or direct deposit update is accepted. Define ownership and escalation paths for high-risk payroll change transactions.
MITRE ATT&CKT1566 — PhishingBEC-style payroll fraud commonly begins with credential or message deception.
Recommendation — Hunt for phishing and impersonation indicators when payroll change requests arrive.

Practitioner Guidance

What to verify: Confirm that payroll changes require a known-good callback or internal approval path that is independent of the incoming request. If the approval channel is derived from the message itself, it is not a meaningful control.

Decision rule: If the request changes where money is sent, treat it as a high-risk transaction until the employee or an authorized delegate confirms it through a pre-established internal process. If you cannot verify through that path, do not execute the change.

Practitioner takeaway: The main objective is to make payroll edits hard to complete with only email access, because BEC succeeds when the organization mistakes message authenticity for transaction authenticity.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org