An employee gets an email that looks exactly like it came from your payroll provider. The logo is right. The tone is right. It says the company's HR portal has switched vendors and everyone needs to re-verify their direct deposit information by end of day. The employee clicks, logs in with their real credentials on a fake page, and two pay cycles later their paycheck is landing in an account they've never seen.
That scenario is now common enough that the IRS put it on its 2026 "Dirty Dozen" list — the agency's annual roundup of the tax scams doing the most damage to individuals and businesses. Phishing and impersonation top the list again this year, but what's new is the specific target: payroll and HR systems, not just individual taxpayers filing a return.
If you run payroll for even a handful of employees, this is worth five minutes of your attention. The scam is cheap to run, hard to reverse once money moves, and it's aimed squarely at the systems small businesses depend on most.
How the Scam Actually Works
Traditional IRS impersonation scams try to scare an individual taxpayer into paying a fake tax bill. The payroll variant is quieter and more patient. Instead of threatening you, it impersonates someone you already trust — a payroll administrator, an HR representative, or a company executive — and asks for something that sounds like routine housekeeping.
The most common versions look like this:
- A fake W-2 or portal notification. An email claims your payroll system has new documents ready or needs a password reset, and links to a convincing but fraudulent login page that captures real credentials.
- A bulk data request. Someone impersonating a company officer emails HR or payroll asking for a spreadsheet of employee names, Social Security numbers, and W-2 information — often timed around tax season when such requests seem plausible.
- A direct-deposit change request. An email, sent as if from an employee or routed through a compromised account, asks payroll to update bank routing and account numbers "before the next pay run." If it's processed outside your normal verification steps, the next paycheck goes straight to the scammer.
Once attackers have login credentials or employee data, they can reroute direct deposits, file fraudulent tax returns using stolen Social Security numbers, or sell the data outright. None of this requires breaking into your systems — it just requires one employee trusting one email.
Why Payroll Is Such an Attractive Target
This isn't a hunch — it shows up in the numbers. The FBI's Internet Crime Complaint Center (IC3) tracks business email compromise (BEC), the umbrella category that includes payroll diversion fraud alongside invoice fraud and executive impersonation. In its 2025 Internet Crime Report, IC3 logged 24,768 BEC complaints totaling roughly $3.05 billion in losses — up from $2.77 billion the year before. Crucially, 86% of BEC losses moved by wire transfer or ACH, the same rails payroll direct deposits run on, which is exactly why these schemes move fast and are so rarely recovered once funds leave the account.
Payroll diversion specifically has a track record of exploding quickly once criminals find a working template. An earlier IC3 advisory found reported losses from payroll diversion scams jumped 815% over an 18-month stretch, as fraud rings realized a single successful redirect can run for one or more full pay cycles before anyone notices — far more efficient than a one-time invoice scam.
A few structural reasons payroll is such a soft target:
- The information is already semi-public. Job titles, department names, and org charts are easy to find on LinkedIn or a company website, which lets scammers write specific, believable emails instead of generic ones.
- The ask sounds routine. "Please update my direct deposit" is a request payroll handles constantly, so it doesn't automatically trigger suspicion the way a request for a wire transfer to an unfamiliar vendor might.
- Younger and higher-income employees are disproportionately targeted. Employees used to managing everything through self-service portals are more likely to trust a portal-styled phishing page, and employees with more complex pay (bonuses, equity, multiple accounts) make attractive, higher-value targets.
Why This Cluster Made the 2026 List Specifically
The Dirty Dozen isn't a static list — the IRS reshuffles it each year based on what's actually working for fraudsters, and this year's edition adds abusive claims tied to Form 2439 undistributed capital gains alongside the usual QR-code phishing and ghost tax preparer entries. Payroll-targeted phishing earning a callout in the same breath as those long-running scams is a signal worth taking seriously: it means the IRS and the financial institutions it works with are seeing this pattern often enough, and at enough dollar volume, to warrant a public warning outside of tax season itself.
Two dynamics are compounding right now. First, generative AI has made it trivial to produce a flawless, typo-free phishing email referencing a real manager's name and a real internal process — the kind of message that used to get caught by "check for bad grammar" training is now indistinguishable from a legitimate one. Second, payroll and HR software vendors have genuinely changed platforms more often in the last few years, so an email claiming "your company switched payroll providers, please re-verify your account" lands as plausible instead of suspicious. Scammers aren't inventing a new lie — they're riding a real trend in how businesses actually operate.
The Warning Signs Experts Point To
Security researchers who study these schemes keep coming back to the same three-word checklist: urgency, unusual requests, and process changes. Any payroll or HR communication that combines a tight deadline with a request that skips your normal verification step deserves a second look, regardless of how legitimate the sender name looks.
Concretely, that means treating these as red flags:
- A direct-deposit change request that arrives by email only, with no phone or in-person verification
- Pressure to act "today" or "before the next pay run," especially outside your normal payroll cutoff schedule
- A request for a bulk export of employee tax or banking data, especially from someone claiming executive authority
- Login pages for your payroll portal that don't match the URL you'd normally bookmark or type directly
How to Protect Your Business
The fix isn't exotic — it's process discipline, applied consistently even when a request looks legitimate.
- Require a second verification channel for any direct-deposit change. A callback to a known phone number, or an in-person confirmation, closes the single biggest hole: an email-only workflow that a phishing page can fully imitate.
- Train employees to recognize the three warning signs above, not just "don't click suspicious links." Generic phishing training doesn't prepare people for an email that looks like it came from their own HR department.
- Report suspected IRS-related phishing to
phishing@irs.govand file an IC3 complaint at ic3.gov if money has already moved — the earlier a bank is notified, the better the odds of clawing back an ACH transfer before it settles. - Restrict who can approve payroll changes. If your payroll software supports approval workflows or dual sign-off for bank detail changes, turn it on. A single point of failure is what these scams are built to exploit.
- Audit your payroll access list. Former employees, old vendor logins, and shared credentials are all easier entry points than a novel hack — and easier to close than most people expect.
If It Already Happened: The First 72 Hours
If a paycheck was rerouted or payroll data was already sent to an attacker, speed matters more than anything else in this list.
- Call the receiving and sending banks immediately. ACH transfers can sometimes be recalled or frozen within a narrow window after the transaction settles — but that window is measured in hours and days, not weeks. Don't wait for a written incident report before making the call.
- Lock down the compromised account or credential. If an employee entered their payroll portal login on a fake page, reset that password and any other account where they reused it, and check for unauthorized email forwarding rules — a classic sign an inbox was quietly compromised before the payroll request went out.
- File with IC3 and notify the IRS. Beyond
phishing@irs.gov, businesses whose employee data was exposed should also review IRS guidance on reporting data breaches, since stolen Social Security numbers can be used to file fraudulent returns months later, not just immediately. - Notify affected employees directly, not just through the same channel that may have been compromised. If their personal data was exposed, they may need to place a fraud alert or credit freeze of their own.
- Document everything for your books. Reversed transactions, replacement payments to the affected employee, and any recovered funds all need to be recorded accurately — a fraud incident that isn't cleanly reconciled tends to resurface as a confusing discrepancy months later.
Keep Your Financial Records Ready for Anything
Payroll fraud isn't just a cybersecurity problem — it's a bookkeeping problem the moment it happens. If a paycheck gets rerouted, you need clean, timestamped records of every payroll run to figure out exactly what changed, when, and who approved it. Beancount.io provides plain-text accounting that gives you a fully version-controlled, auditable trail of every transaction — no black boxes, no vendor lock-in, and no guessing what your books looked like before something went wrong. Get started for free and see why developers and finance professionals are switching to plain-text accounting.