PanicStation.org
us Work & employment crises

What to do if…
you receive a suspicious email asking you to change your payroll or direct deposit bank details

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Do not act from the email. Verify through a known HR or payroll route, then alert HR, payroll, and IT or security so they can protect your direct deposit and check for compromise.

Do not do these things

  • Do not click the link or open attachments, even if the message looks like your payroll portal.
  • Do not reply to the message or continue the conversation by email or text.
  • Do not call any phone number in the message or use any helpdesk link it provides.
  • Do not change direct deposit details based only on an email request.
  • Do not forward it broadly to coworkers; send it only to the correct internal reporting channel.
  • If you already clicked, entered credentials, or changed details, do not wait until payday to see what happens.

What to do now

  1. Verify through a trusted route you already know.
    Contact HR or payroll using your employee directory, handbook, company intranet, or another trusted internal route. Ask: “Did you request a change to my direct deposit details?”

  2. Open your payroll portal without using the email.
    Use the bookmark, typed address, company intranet, or app you normally use. Check for recent changes to direct deposit, contact details, security settings, MFA settings, and password-reset notices you did not start.

  3. Ask payroll to pause direct deposit changes on your profile.
    Request a temporary hold on any direct deposit change until you confirm through the employer’s normal identity checks. If payday is close, ask payroll to confirm which account your next pay is scheduled to use and whether any change is pending.

  4. Report the message to IT or security.
    Use your company’s official reporting method, such as a phishing-report button, security inbox, or service desk. Include that the message asked for payroll bank details or direct deposit changes.

  5. If you clicked or entered credentials, treat it as a possible account compromise.
    Change your work password from the legitimate login page, not from the email. Turn on MFA if available, or ask IT to help. Tell IT what you clicked, what you entered, and whether you reused that password anywhere else.

  6. If you entered or changed bank details, tell payroll and your bank now.
    Ask payroll whether any direct deposit change was submitted or approved. Contact your bank through the number on your card, statement, or banking app and ask what they can do to monitor, stop, or help document any suspicious transfer.

  7. If personal information was shared, reduce identity-theft risk.
    Tell HR or payroll what was shared, such as routing number, account number, address, date of birth, or Social Security number. If your Social Security number or other high-risk information was exposed, use official identity-theft guidance and consider a fraud alert or credit freeze.

  8. Report externally if money was diverted or the attempt is serious.
    You can file a complaint with the FBI’s Internet Crime Complaint Center and report the scam to the Federal Trade Commission. If you file an IC3 complaint about this scheme, describe it as payroll diversion.

What can wait

  • You do not need to investigate the sender or argue with them.
  • You do not need to warn everyone yourself before HR, payroll, or IT has the message.
  • You do not need to decide today whether to close accounts or take legal steps unless payroll, your bank, or official identity-theft guidance says urgent action is needed.
  • Longer-term security improvements can wait until HR, payroll, and IT have confirmed whether your payroll record or account was changed.

Important reassurance

This kind of message is designed to make a routine payroll task feel urgent. Pausing is the right move. The useful next step is not to solve the whole scam yourself, but to verify through known channels and get the right internal teams involved.

Scope note

These are first steps to prevent paycheck diversion and contain a possible account compromise. Later decisions may need help from your employer, bank, identity-theft resources, law enforcement, or another qualified specialist.

Important note

This guide is general information, not legal, financial, cybersecurity, employment, or other professional advice. Employer policies, payroll systems, banks, and state rules can differ. Follow your employer’s official security process and your financial institution’s instructions.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us