Payroll & Tax Fraud
- Payroll fraud is much more than the BEC redirect scam. It covers processor account takeover, W2 theft, ghost employees, 1099 manipulation and withholding fraud
- One W2 breach exposes every employee's SSN, address and income. That's enough to file fake tax returns at scale
- Payroll processor ATO is the worst of them. Someone gets your Gusto or ADP admin login. Now they hold your banking, your tax data and everyone's PII
- Prevention is MFA, separation of duties, dual approval on bank changes and a quarterly audit. Most SMBs run none of it
Payroll fraud is theft that runs through your payroll system. Redirected deposits, stolen W2 files, invented employees, tampered withholding.
Ask an SMB about payroll fraud and you'll hear about the direct deposit redirect. Someone impersonates an employee and HR changes the bank account. That's real, and it's covered on the BEC & Phishing page. The rest of the landscape is bigger, and it hurts more. Take over a payroll admin account and you don't redirect one paycheck. You get every employee's SSN. You get every bank account on file. You can invent people and pay them. This page is about the attacks nobody's watching for.
How This Differs from BEC Payroll Redirect
The BEC redirect is one social engineering trick. It's the tip. Here's the rest of the iceberg:
| Attack | Vector | Target | Impact | Detection Difficulty |
|---|---|---|---|---|
| BEC payroll redirect | Email impersonation of employee | HR/payroll staff | Single paycheck redirected ($3K-$15K) | Low - employee reports missing pay |
| Payroll processor ATO | Credential theft/phishing of admin | Gusto/ADP/Paychex account | Full access to all employee data, banking, tax info | Medium - changes may look legitimate |
| W2 data theft | Platform breach or insider access | Employee tax records | Mass identity theft, fraudulent tax returns | High - often not detected until tax season |
| Ghost employee scheme | Insider creates fictitious workers | Payroll itself | Ongoing theft per pay period | High - requires payroll-to-HR reconciliation |
| 1099 manipulation | Insider or ATO | Contractor payments | Diverted payments, false deductions | High - contractors may not notice for months |
| Tax withholding fraud | ATO or insider | Withholding settings | Redirected tax payments, employee tax debt | Very high - surfaces at year-end filing |
Key distinction: the BEC redirect works on your people, while everything on this page works on your systems and your platform access. Different problem, different defenses.
Payroll Processor Account Takeover
This is the worst one. Someone gets into your admin account on Gusto, ADP or Paychex, and they hold the keys to everything.
How They Get In
- Credential phishing - A fake login page. Most common by far
- Credential stuffing - Your admin reused a breached password
- Session hijacking - Malware on the laptop grabs a live session
- Calling the vendor - They phone ADP support pretending to be you
What They Do Once In
With admin access they can:
- Change employee bank accounts - Several deposits redirected at once
- Add ghost employees - Fake workers, paid to accounts they own
- Export W2 data - Every SSN and income figure you've ever filed
- Modify withholding - Bigger take-home pay on the checks they're stealing
- Change company banking - Your funding account, not an employee's
- Add themselves as admin - A backdoor that outlives the password reset
Why this beats BEC: a redirect gets one paycheck, while processor ATO gets everything. And the access can sit there for weeks.
Real-World Pattern
The typical attack plays out over 3-7 days:
- Day 1: They get in and export the employee file
- Day 2-3: Small test changes. One bank account, one withholding
- Day 4-5: Nobody noticed. Now come the ghost employees and the bulk bank changes
- Day 6-7: Payroll runs. They cash out and leave a hidden admin behind
W2 & Tax Data Theft
W2 theft is seasonal. Attacks spike January through April. That's filing season, and a stolen W2 turns into a refund check fast.
Why W2 Data Is So Valuable
A single W2 carries everything an identity thief needs:
- Full legal name and SSN
- Home address
- Total income, so the fake return looks right
- Employer EIN, which sells the fake return to the IRS
One breach, every employee. A platform breach or a single insider export puts every name in the system at risk. Former staff too.
How Stolen W2 Data Gets Used
- Fraudulent tax returns - Filed before the real employee files. Average fake refund runs $5,000-$8,000
- Identity theft - The SSN opens credit lines, loans and synthetic identities
- Sold on dark web - $20-$50 a record. Fifty employees is $1,000-$2,500 on the spot
Seasonal Defense Calendar
| Month | Action |
|---|---|
| November | Audit payroll platform access; remove former employees and unnecessary admins |
| December | Enable MFA on all payroll accounts; verify admin contact info |
| January | Lock down W2 generation; restrict who can view/download |
| February-April | Monitor for unusual data exports; watch for employee reports of rejected tax returns |
| Year-round | Quarterly access reviews; log monitoring |
Do the November row properly and the January row gets easier. Every account you remove before the W2 file exists is one that can't export it.
Ghost Employee & 1099 Schemes
Ghost employee fraud is almost always an insider. Someone with payroll access invents a worker, and the pay lands in an account they control.
Ghost Employee Red Flags
- No matching record in the HR system, payroll only
- Same bank account used for two or more employees
- Address matches another employee or the payroll admin
- No benefits, no training records, no badge
- Round-number salaries that don't match any pay grade
- "Hired" by the same person who runs payroll
1099 Contractor Manipulation
Fake contractors are harder to spot than ghost employees, because they skip onboarding entirely.
- Fake contractors - Invented to siphon payments. The business names sound real
- Inflated invoices - Real contractor, padded amount, kickback to the approver
- Duplicate payments - Same invoice paid twice. The second one lands elsewhere
Detection Approach
| Check | Frequency | What You're Looking For |
|---|---|---|
| Payroll-to-HR reconciliation | Monthly | Employees on payroll but not in HR system |
| Bank account duplication scan | Each pay run | Multiple employees sharing a bank account |
| Address matching | Quarterly | Employee addresses matching admin or each other |
| 1099 vendor verification | Quarterly | Contractors with no contract, no deliverables, no contact info |
| Payroll variance analysis | Each pay run | Unexplained increases in total payroll amount |
Tax Withholding Manipulation
This is the quiet one. It can run a full tax year unnoticed.
How It Works
- Reducing withholding - Max exemptions on the W4. Bigger checks to steal
- Redirecting tax deposits - Some platforms let you configure this by hand
- Changing contributions - The 401(k) match, the HSA, any pre-tax deduction
Why It's Hard to Detect
A withholding change looks like normal self-service. Anyone can update a W4 any day of the year. You find out when:
- Employees get surprise tax bills at year-end
- Quarterly deposits don't match what you expected
- Year-end W2 totals won't reconcile with payroll records
None of those is a control. They're all after the fact.
Prevention Controls
Three of the controls below carry most of the weight for a small business: MFA on every payroll account, dual approval on bank account changes, and the payroll-to-HR reconciliation. MFA blocks the credential attacks, dual approval blocks the redirect, and the reconciliation is what surfaces a ghost. Do those three before you touch IP allowlisting or session timeouts.
Platform Security
| Control | Why It Matters |
|---|---|
| MFA on all payroll accounts | Blocks credential stuffing and most phishing attacks |
| Role-based access | Not everyone needs admin; most need view-only or self-service |
| IP allowlisting | Restrict admin access to office network or VPN |
| Session timeout | 15-minute idle timeout for payroll admin sessions |
| Audit logging | Every change logged with who, what, when, and from where |
Process Controls
| Control | Why It Matters |
|---|---|
| Separation of duties | Person who adds employees should not be the person who approves payroll |
| Dual approval for banking changes | Any bank account change requires a second approver |
| 48-hour lock before pay run | No changes allowed within 48 hours of payroll processing |
| Quarterly payroll audit | Reconcile payroll roster against HR records, verify all bank accounts |
| Annual W2 access review | Restrict who can generate, view, or download W2s |
Monitoring
| Signal | Response |
|---|---|
| New admin account created | Verify immediately with company owner |
| Bulk data export (W2s, employee list) | Confirm business purpose within 1 hour |
| Multiple bank account changes before pay run | Hold payroll; verify each change |
| New employee added without HR ticket | Freeze until HR confirms |
| Withholding changes for multiple employees simultaneously | Review each change individually |
If You're Compromised
Found unauthorized access, or you suspect payroll fraud? Work these in order.
Immediate (First 2 Hours)
- Lock the platform - New admin passwords. Kill every live session. Disable anything suspicious
- Hold the next pay run - Nothing goes out until you've checked every setting
- Preserve evidence - Export the audit logs before you change anything. Note the timeline
Within 24 Hours
- Notify affected employees - Their SSN and bank details may be out. Be direct about what leaked
- Point them at IRS Form 14039, the Identity Theft Affidavit - It flags the SSN, so fake returns get a second look
- File a police report - Insurance and regulators both want one
- Notify your state Attorney General - Most states set a 30-72 day clock. Check yours
Within 72 Hours
- Contact the IRS - If W2 data leaked, email dataloss@irs.gov. Subject line: "W2 Data Loss"
- Offer credit monitoring - 12 to 24 months free is the norm
- Audit every payroll change - Go back 90 days. Match each change to a real request
Ongoing
- Rebuild platform security - New admin accounts, MFA, IP limits, less access
- Document everything - Law enforcement, insurance and lawyers all want the timeline
- Consider forensics - A platform-level breach puts your provider in the room
Next Steps
Securing your payroll platform?
- Turn on MFA for every payroll admin today. It blocks most ATO
- Require two approvers for any bank account change
- Book your first payroll-to-HR reconciliation. That's how ghosts surface
Worried about tax season exposure?
- Lock down W2 access before January. One named person generates and downloads
- Read the BEC & Phishing page for the email side
- Set an alert on bulk data exports
Already dealing with a breach?
- Follow the If You're Compromised playbook above. Lockdown first
- Read the Survive a Fraud Attack playbook next
- Check Business Banking ATO if bank logins leaked too
Related Pages
- BEC & Phishing - Payroll redirect by email impersonation
- Account Takeover - ATO concepts, applied to payroll platforms
- Business Banking ATO - When they go straight at your bank
- Fraud Types Overview - The full taxonomy
- Who Owns What - Roles and separation of duties
- Survive a Fraud Attack - Emergency response
- Identity Verification - MFA and verification controls