Skip to main content

Payroll & Tax Fraud

TL;DR
  • Payroll fraud is much more than the BEC redirect scam. It covers processor account takeover, W2 theft, ghost employees, 1099 manipulation and withholding fraud
  • One W2 breach exposes every employee's SSN, address and income. That's enough to file fake tax returns at scale
  • Payroll processor ATO is the worst of them. Someone gets your Gusto or ADP admin login. Now they hold your banking, your tax data and everyone's PII
  • Prevention is MFA, separation of duties, dual approval on bank changes and a quarterly audit. Most SMBs run none of it

Payroll fraud is theft that runs through your payroll system. Redirected deposits, stolen W2 files, invented employees, tampered withholding.

Ask an SMB about payroll fraud and you'll hear about the direct deposit redirect. Someone impersonates an employee and HR changes the bank account. That's real, and it's covered on the BEC & Phishing page. The rest of the landscape is bigger, and it hurts more. Take over a payroll admin account and you don't redirect one paycheck. You get every employee's SSN. You get every bank account on file. You can invent people and pay them. This page is about the attacks nobody's watching for.

How This Differs from BEC Payroll Redirect

The BEC redirect is one social engineering trick. It's the tip. Here's the rest of the iceberg:

AttackVectorTargetImpactDetection Difficulty
BEC payroll redirectEmail impersonation of employeeHR/payroll staffSingle paycheck redirected ($3K-$15K)Low - employee reports missing pay
Payroll processor ATOCredential theft/phishing of adminGusto/ADP/Paychex accountFull access to all employee data, banking, tax infoMedium - changes may look legitimate
W2 data theftPlatform breach or insider accessEmployee tax recordsMass identity theft, fraudulent tax returnsHigh - often not detected until tax season
Ghost employee schemeInsider creates fictitious workersPayroll itselfOngoing theft per pay periodHigh - requires payroll-to-HR reconciliation
1099 manipulationInsider or ATOContractor paymentsDiverted payments, false deductionsHigh - contractors may not notice for months
Tax withholding fraudATO or insiderWithholding settingsRedirected tax payments, employee tax debtVery high - surfaces at year-end filing

Key distinction: the BEC redirect works on your people, while everything on this page works on your systems and your platform access. Different problem, different defenses.


Payroll Processor Account Takeover

This is the worst one. Someone gets into your admin account on Gusto, ADP or Paychex, and they hold the keys to everything.

How They Get In

  • Credential phishing - A fake login page. Most common by far
  • Credential stuffing - Your admin reused a breached password
  • Session hijacking - Malware on the laptop grabs a live session
  • Calling the vendor - They phone ADP support pretending to be you

What They Do Once In

With admin access they can:

  1. Change employee bank accounts - Several deposits redirected at once
  2. Add ghost employees - Fake workers, paid to accounts they own
  3. Export W2 data - Every SSN and income figure you've ever filed
  4. Modify withholding - Bigger take-home pay on the checks they're stealing
  5. Change company banking - Your funding account, not an employee's
  6. Add themselves as admin - A backdoor that outlives the password reset

Why this beats BEC: a redirect gets one paycheck, while processor ATO gets everything. And the access can sit there for weeks.

Real-World Pattern

The typical attack plays out over 3-7 days:

  • Day 1: They get in and export the employee file
  • Day 2-3: Small test changes. One bank account, one withholding
  • Day 4-5: Nobody noticed. Now come the ghost employees and the bulk bank changes
  • Day 6-7: Payroll runs. They cash out and leave a hidden admin behind

W2 & Tax Data Theft

W2 theft is seasonal. Attacks spike January through April. That's filing season, and a stolen W2 turns into a refund check fast.

Why W2 Data Is So Valuable

A single W2 carries everything an identity thief needs:

  • Full legal name and SSN
  • Home address
  • Total income, so the fake return looks right
  • Employer EIN, which sells the fake return to the IRS

One breach, every employee. A platform breach or a single insider export puts every name in the system at risk. Former staff too.

How Stolen W2 Data Gets Used

  1. Fraudulent tax returns - Filed before the real employee files. Average fake refund runs $5,000-$8,000
  2. Identity theft - The SSN opens credit lines, loans and synthetic identities
  3. Sold on dark web - $20-$50 a record. Fifty employees is $1,000-$2,500 on the spot

Seasonal Defense Calendar

MonthAction
NovemberAudit payroll platform access; remove former employees and unnecessary admins
DecemberEnable MFA on all payroll accounts; verify admin contact info
JanuaryLock down W2 generation; restrict who can view/download
February-AprilMonitor for unusual data exports; watch for employee reports of rejected tax returns
Year-roundQuarterly access reviews; log monitoring

Do the November row properly and the January row gets easier. Every account you remove before the W2 file exists is one that can't export it.


Ghost Employee & 1099 Schemes

Ghost employee fraud is almost always an insider. Someone with payroll access invents a worker, and the pay lands in an account they control.

Ghost Employee Red Flags

  • No matching record in the HR system, payroll only
  • Same bank account used for two or more employees
  • Address matches another employee or the payroll admin
  • No benefits, no training records, no badge
  • Round-number salaries that don't match any pay grade
  • "Hired" by the same person who runs payroll

1099 Contractor Manipulation

Fake contractors are harder to spot than ghost employees, because they skip onboarding entirely.

  • Fake contractors - Invented to siphon payments. The business names sound real
  • Inflated invoices - Real contractor, padded amount, kickback to the approver
  • Duplicate payments - Same invoice paid twice. The second one lands elsewhere

Detection Approach

CheckFrequencyWhat You're Looking For
Payroll-to-HR reconciliationMonthlyEmployees on payroll but not in HR system
Bank account duplication scanEach pay runMultiple employees sharing a bank account
Address matchingQuarterlyEmployee addresses matching admin or each other
1099 vendor verificationQuarterlyContractors with no contract, no deliverables, no contact info
Payroll variance analysisEach pay runUnexplained increases in total payroll amount

Tax Withholding Manipulation

This is the quiet one. It can run a full tax year unnoticed.

How It Works

  • Reducing withholding - Max exemptions on the W4. Bigger checks to steal
  • Redirecting tax deposits - Some platforms let you configure this by hand
  • Changing contributions - The 401(k) match, the HSA, any pre-tax deduction

Why It's Hard to Detect

A withholding change looks like normal self-service. Anyone can update a W4 any day of the year. You find out when:

  • Employees get surprise tax bills at year-end
  • Quarterly deposits don't match what you expected
  • Year-end W2 totals won't reconcile with payroll records

None of those is a control. They're all after the fact.


Prevention Controls

Three of the controls below carry most of the weight for a small business: MFA on every payroll account, dual approval on bank account changes, and the payroll-to-HR reconciliation. MFA blocks the credential attacks, dual approval blocks the redirect, and the reconciliation is what surfaces a ghost. Do those three before you touch IP allowlisting or session timeouts.

Platform Security

ControlWhy It Matters
MFA on all payroll accountsBlocks credential stuffing and most phishing attacks
Role-based accessNot everyone needs admin; most need view-only or self-service
IP allowlistingRestrict admin access to office network or VPN
Session timeout15-minute idle timeout for payroll admin sessions
Audit loggingEvery change logged with who, what, when, and from where

Process Controls

ControlWhy It Matters
Separation of dutiesPerson who adds employees should not be the person who approves payroll
Dual approval for banking changesAny bank account change requires a second approver
48-hour lock before pay runNo changes allowed within 48 hours of payroll processing
Quarterly payroll auditReconcile payroll roster against HR records, verify all bank accounts
Annual W2 access reviewRestrict who can generate, view, or download W2s

Monitoring

SignalResponse
New admin account createdVerify immediately with company owner
Bulk data export (W2s, employee list)Confirm business purpose within 1 hour
Multiple bank account changes before pay runHold payroll; verify each change
New employee added without HR ticketFreeze until HR confirms
Withholding changes for multiple employees simultaneouslyReview each change individually

If You're Compromised

Found unauthorized access, or you suspect payroll fraud? Work these in order.

Immediate (First 2 Hours)

  1. Lock the platform - New admin passwords. Kill every live session. Disable anything suspicious
  2. Hold the next pay run - Nothing goes out until you've checked every setting
  3. Preserve evidence - Export the audit logs before you change anything. Note the timeline

Within 24 Hours

  1. Notify affected employees - Their SSN and bank details may be out. Be direct about what leaked
  2. Point them at IRS Form 14039, the Identity Theft Affidavit - It flags the SSN, so fake returns get a second look
  3. File a police report - Insurance and regulators both want one
  4. Notify your state Attorney General - Most states set a 30-72 day clock. Check yours

Within 72 Hours

  1. Contact the IRS - If W2 data leaked, email dataloss@irs.gov. Subject line: "W2 Data Loss"
  2. Offer credit monitoring - 12 to 24 months free is the norm
  3. Audit every payroll change - Go back 90 days. Match each change to a real request

Ongoing

  1. Rebuild platform security - New admin accounts, MFA, IP limits, less access
  2. Document everything - Law enforcement, insurance and lawyers all want the timeline
  3. Consider forensics - A platform-level breach puts your provider in the room

Next Steps

Securing your payroll platform?

  1. Turn on MFA for every payroll admin today. It blocks most ATO
  2. Require two approvers for any bank account change
  3. Book your first payroll-to-HR reconciliation. That's how ghosts surface

Worried about tax season exposure?

  1. Lock down W2 access before January. One named person generates and downloads
  2. Read the BEC & Phishing page for the email side
  3. Set an alert on bulk data exports

Already dealing with a breach?

  1. Follow the If You're Compromised playbook above. Lockdown first
  2. Read the Survive a Fraud Attack playbook next
  3. Check Business Banking ATO if bank logins leaked too