Employers MyEnroll360 Security

Common Business Email Compromise Scams Targeting HR and Payroll

Business Email Compromise (BEC) scams continue to be one of the most costly cyber threats facing employers.

3 min read By BAS Knowledge Team
Illustration of a masked scammer phishing for credit card and financial data through a laptop screen, representing business email compromise scams

Unlike traditional phishing attacks that rely on malicious links or attachments, BEC scams often involve emails that appear to come from a trusted source, such as a company executive, employee, vendor, or benefits provider. Their goal is to convince someone in HR or Payroll to take an action that results in financial loss or the unauthorized disclosure of sensitive information.

Because HR and Payroll teams routinely handle employee personal information, payroll records, direct deposit changes, and benefits data, they are frequent targets of these attacks.

Common BEC Scams

Some of the most common schemes include:

  • Direct Deposit Changes: An attacker impersonates an employee and requests that payroll update direct deposit information before the next payroll run.
  • W-2 or Employee Data Requests: An email appearing to come from an executive asks HR to immediately send employee W-2 forms, Social Security numbers, or personnel records.
  • Benefits or Enrollment Changes: Fraudsters pose as employees requesting changes to beneficiaries, dependents, or health plan elections using compromised or spoofed email accounts.
  • Vendor Payment Fraud: An attacker impersonates a vendor and requests that future payments be sent to a new bank account.
  • Executive Impersonation: An email that appears to come from a senior executive requests an urgent payment, confidential employee information, or immediate action while emphasizing secrecy or urgency.

Warning Signs

While these emails often look legitimate, they frequently contain subtle warning signs, including:

  • An unexpected request involving payroll, banking, or employee information.
  • A sense of urgency or pressure to act immediately.
  • A request to bypass normal approval procedures.
  • A new email address that closely resembles a legitimate one.
  • Slightly unusual wording, grammar, or formatting.
  • A request to communicate only by email rather than by telephone.

Best Practices for HR and Payroll

Strong internal procedures are often the best defense against these attacks. Consider the following practices:

  • Independently verify any request to change direct deposit or banking information by calling the employee or vendor using a known telephone number.
  • Never rely solely on an email request to release employee records or modify payroll or benefit information.
  • Require dual approval for sensitive payroll or banking changes whenever practical.
  • Confirm unusual requests from executives through a separate communication method.
  • Report suspicious emails immediately to your IT or information security team, even if no information was disclosed.

Employer Takeaway

Cybercriminals increasingly rely on social engineering rather than technical hacking to gain access to sensitive information. A few extra minutes spent verifying an unexpected request can prevent payroll fraud, identity theft, and unauthorized disclosure of employee data. By following established procedures and encouraging employees to question unusual requests, HR and Payroll professionals remain one of an organization’s strongest defenses against business email compromise.

Benefit Allocation Systems (BAS) provides online solutions for: Employee Benefits Enrollment; COBRA; Flexible Spending Accounts (FSAs); Health Reimbursement Accounts (HRAs); Leave of Absence Premium Billing (LOA); Affordable Care Act Record Keeping, Compliance & IRS Reporting (ACA); Group Insurance Premium Billing; Property & Casualty Premium Billing; and Payroll Integration.

MyEnroll360 integrates with major insurance carriers for enrollment eligibility management (e.g., Blue Cross, Blue Shield, Aetna, United Health Care, Kaiser, CIGNA and others), and with leading payroll platforms for enrollment deduction management (e.g., Workday, ADP, Paylocity, PayCor, UKG, and others).

This article is for informational purposes only and is not intended as legal, tax, or benefits advice. Readers should not rely on this information for taking (or not taking) any action relating to employment, compliance, or benefits. Always consult with a qualified professional before making decisions based on this content.

Topics
MyEnroll360 Security Security Employers

Benefits Administration Updates

Receive Benefits Administration Updates from BAS

Practical compliance and administration guidance delivered directly to your inbox. Unsubscribe anytime.