Salary Payment Fraud: Why Employee Bank Detail Changes Are an HR Blind Spot
An employee informs HR that they’ve changed banks. The request arrives by email with a new bank account (RIB) attached. At first glance, nothing seems unusual.
The change is processed through the usual workflow. The salary is paid.
A few days later, the employee reports never receiving payment.
The money was indeed sent… but to a fraudulent account.
This type of scenario illustrates an increasingly common reality: fraud doesn’t rely on complex technical attacks, but on exploiting standard HR processes.
This fraud is growing sharply in France. It’s estimated to target around 200,000 employees each year, according to figures cited by fraud-prevention organizations. The principle remains the same: divert a salary by exploiting a simple bank detail change request
What Is Employee Bank Detail Change Fraud?
How Salary Payment Fraud Works
Employee bank detail change fraud involves impersonating an employee in order to change their bank details and divert their salary.
In most observed cases, this fraud relies on simple identity theft, without complex technical intrusion. It draws on basic information about the employee (role, identity, organization) to make the request credible.
The scenario usually unfolds as follows:
Banking partners and specialized organizations estimate that fake-employee fraud accounts for around 34% of recorded payment fraud cases, with an average loss of around €7,000 per incident.
Why HR and Payroll Teams Are Prime Targets
Regular, Predictable Payments
This trend is reinforced by changing work patterns, particularly remote work and the decentralization of certain HR functions, which make it harder to standardize checks.
Payroll processes rest on a delicate balance between rigor and operational efficiency.
Salaries follow a fixed, known, automated cycle.
This regularity makes payment flows especially exploitable once a change of bank details has been validated.
An Operational Workload That Limits Checks
Payroll teams simultaneously manage:
In this context, the level of verification per transaction can be reduced due to volume constraints.
The Trust Factor in Employee Communications
A request from an employee is rarely questioned, especially when it follows the usual patterns of internal communication.
Fraudsters also exploit the ability to replicate credible exchanges, sometimes with repeated phrasing and follow-up messages to speed up processing of the bank detail change.
The Three Payroll Flows Most Exposed to Fraud
Salaries: A Massive, Automated Flow
Not all payroll flows carry the same level of risk.
Salaries make up the most critical flow:
A single bank detail change is enough to divert several payments.
Expense Claims: High Volume, Low Vigilance
Expense claims are characterized by:
Bonuses: High-Value Targets
Bonuses are particularly targeted because:
Why HR Fraud Is a Systemic Blind Spot
Strong Vendor Controls, Weak Employee Controls
Companies have strengthened their security measures around external third parties, but less so around their own employees at the point of payment.
Organizations systematically verify:
But rarely apply the same level of verification to employee bank detail changes.
The Gap Between Onboarding and Payment
Identity is generally verified at hiring, but rarely re-validated during:
The Bank Account’s Critical Role as an Identifier
The bank account becomes a key operational identifier, but one that’s often not revalidated over time.
Real-World Case: A Bank Detail Change Treated as a Normal Request
A Change Request Received by HR
In a real case reported in France, an employee discovered that her salary had been redirected to another account after a spoofed email was sent to her HR department. The email, signed with her name, explicitly requested a bank detail update, with follow-up messages to speed up the payment.
The message follows the usual patterns of HR communication:
A Change of Details Processed Without Apparent Anomaly
The internal process is applied normally:
Fraud Discovered Only After the Employee’s Complaint
In this type of case, fraud is generally detected only after the fact, when the employee reports not receiving payment, once the funds have already been transferred.
The fraudster had replicated a level of credibility sufficient to fool the internal process, despite existing controls.
What Automated Verification Changes
Identity/IBAN Match Verification
Automated verification transforms this vulnerability point by introducing a systematic check of the payee before the payment is executed.
Every bank detail change is automatically checked to ensure the account matches the declared identity.
Detecting Fraud Attempts Before Payment
Anomalies can be identified upstream:
Traceability and Compliance of Bank Detail Changes
Every change is logged and audited, strengthening:
Best Practices for Securing HR Payments
Dual Validation of Bank Detail Changes
A few key measures can significantly reduce the risk.
Implement independent validation for sensitive bank detail changes.
Training HR Teams on Phishing
Train teams to recognize warning signs:
Automating Bank Verification Checks
Reduce reliance on manual checks by automating IBAN verification.
Salary payment fraud doesn’t rely on sophisticated attacks, but on the exploitation of standard internal processes.
The real point of vulnerability lies at the moment bank details are changed and the payee is validated.
Salary payment fraud today represents a significant share of payment fraud cases, estimated at around a third of recorded payment fraud, with average losses close to €7,000 per incident.

