What to do if…
you receive a suspicious email asking you to change your payroll or direct deposit bank details
Short answer
Pause and do not use anything in the email. Verify the request through a trusted payroll or HR route, and report it to your IT or security team so they can protect your pay and warn others.
Do not do these things
- Don’t click links or open attachments in the message, including “HR forms” or “secure portal” links.
- Don’t reply to the email to confirm details or ask questions.
- Don’t use any phone number, WhatsApp contact, QR code, or helpdesk link provided in the email.
- Don’t change payroll bank details based only on an email request, even if it looks senior, urgent, or familiar.
- Don’t forward the email widely to colleagues; send it only through your organisation’s reporting route.
- If you clicked a link, entered details, or changed anything, don’t wait until payday to raise it.
What to do now
-
Stop and verify through a trusted route.
Use a known payroll or HR contact from your intranet, employee handbook, official directory, previous payslip, or a letter you already trust. Ask: “Did you request a change to my payroll bank details today?” -
Check your payroll or self-service account from the normal route.
Do not use the email link. Open the payroll or HR portal using a saved bookmark, typed address, or your organisation’s normal sign-in route. Look for recent changes to bank details, email address, phone number, password, or recovery details. -
Ask payroll to protect your record.
Ask payroll or HR to put a temporary hold or extra verification on any bank-detail change for your record until you confirm through a verified method. If a payroll run is close, ask them to confirm which account your next pay is scheduled to go to. -
Report the email to IT or security immediately.
Use your organisation’s phishing button, service desk, or cyber-security contact. Tell them whether you clicked anything, downloaded anything, entered a password, approved a sign-in, or changed bank details. -
If you clicked or typed credentials, treat the account as at risk.
From the real sign-in page, change your work password if your organisation allows you to. Ask IT to check for active sessions, password reset activity, mailbox rules, and multi-factor authentication protection. -
If your pay may have been diverted, contact payroll and your bank now.
Ask payroll where the payment is due to go and whether it can still be stopped or corrected. If money has gone, or may go, to the wrong account, contact your bank and ask what they can do to stop, trace, or recall the payment. -
Report the suspicious email to the UK phishing reporting service.
Forward the email to [email protected]. Do this before deleting it if you can. -
If you lost money, were hacked, or shared sensitive details, use the police reporting route for your nation.
If you are in England, Wales, or Northern Ireland, use Report Fraud. If you are in Scotland, contact Police Scotland through 101 for non-emergency reporting, or 999 if there is immediate danger or a crime is happening now.
What can wait
- You do not need to prove it is a scam before pausing the request.
- You do not need to confront the sender or investigate where the email came from.
- You do not need to decide today about wider identity checks, a new bank account, or workplace policy changes unless payroll, IT, your bank, or the police tell you it is urgent.
- You can deal with longer clean-up after you know whether your payroll details, work account, or pay have been affected.
Important reassurance
Payroll bank-detail scams rely on urgency and uncertainty. Pausing, using a trusted route, and involving payroll and IT is a normal protective response, not an overreaction.
Scope note
These are first steps only: stop the possible payment diversion, protect your work account, and get the right people involved. Later decisions about fraud reporting, workplace investigation, bank recovery, or identity protection may need specialist help.
Important note
This guide provides general information only. It is not legal, financial, cyber-security, employment, or professional advice. Follow your organisation’s payroll and IT procedures where they exist, and treat any lost money, changed payroll details, or unauthorised account access as urgent.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.