# Payroll Fraud: Insider Schemes, Diversion Scams, and Controls | RankShield Financial

> Payroll fraud comes from two directions: insiders who game payroll and outsiders who divert a paycheck. Why each needs its own control, and how to close both.
>
> Source: https://rankshieldfinancial.com/resources/payroll-fraud-prevention/ · RankShield Financial (verifiable pre-settlement payment security)

RankShield Network · Financial · Payment Fraud
# Payroll Fraud: The Insider Schemes, the Diversion Scams, and How to Stop Both

Payroll fraud comes from two very different directions: employees who game the payroll from the inside, and outsiders who divert a paycheck from the outside. They need different controls, and confusing them is why businesses leave one door open. Here is how to close both.
   By  Jamie Kloncz  Founder, RankShield Financial    August 18, 2026 · 12 min read               Key takeaways
- Payroll fraud comes from two directions that need different defenses. Internal schemes are insiders gaming the payroll (ghost employees, padded hours, inflated commissions); external diversion is outsiders rerouting a real paycheck by changing direct-deposit details.
- Internal payroll fraud is occupational fraud. Asset misappropriation, which includes payroll schemes, appears in 90 percent of ACFE cases, and organizations with fewer than 100 employees suffer the highest median loss of any size, $126,000, because one person controls too much of the process.
- External payroll diversion is business email compromise aimed at HR or payroll: a spoofed request to update an employee’s bank details reroutes the next paycheck to the fraudster. The employer, not the employee, typically absorbs the loss, and self-service portals do not stop it.
- The controls are different by design. Internal schemes are caught by separation of duties, roster and change review, and audit; external diversion is stopped by verifying any banking-detail change out of band before the payroll run. A business needs both, not one.
- RankShield Financial addresses the external side and the outbound payment: it verifies a payee bank change and a named approval before payroll settles, and seals a record. It does not audit timesheets or detect ghost employees, which remain a matter of internal controls.

Payroll fraud is one label for two genuinely different problems, and treating them as one is why businesses keep leaving a door open. The first kind comes from inside: an employee or manager games the payroll itself, through a ghost employee, padded hours, or an inflated commission. The second comes from outside: a fraudster diverts a real employee’s paycheck by changing the direct-deposit details, usually through a spoofed email to payroll or HR. These are committed by different people, exploit different weaknesses, and are stopped by different controls, so a business that hardens one while ignoring the other is still exposed. Internal payroll schemes fall under what the ACFE calls occupational fraud, where asset misappropriation appears in 90 percent of cases and the typical organization loses about 5 percent of revenue to fraud 1 . External diversion is a form of business email compromise, which the FBI put at $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH 2 . This guide separates the two families, explains how each works, and shows the controls that close both doors.

## Two families of payroll fraud, and why the distinction matters

The single most useful thing to understand about payroll fraud is that it arrives from two directions, and the two have almost nothing in common except the word payroll. Internal payroll fraud is committed by people inside the organization, employees, managers, or whoever controls the payroll process, who manipulate it to pay out money that should not be paid, to themselves or an accomplice. External payroll fraud, usually called payroll diversion, is committed by outsiders who never touch your systems; they simply deceive your HR or payroll staff into sending a real employee’s pay to an account the fraudster controls. One is an abuse of trust from within; the other is a deception from without.

This distinction is not academic, because the two families are stopped by entirely different controls, and confusing them leaves a real gap. A business that installs strong separation of duties and audits its payroll register has hardened itself against the insider schemes, and may believe it has solved payroll fraud, while remaining completely open to an emailed direct-deposit change that reroutes a paycheck. The reverse is also true: a company that trains staff to verify banking changes has closed the external door while a ghost employee quietly draws a salary inside. Naming the two families is the first step, because you cannot close a door you have not noticed is there.

## The insider schemes: how payroll gets gamed from within

Internal payroll fraud is a category of occupational fraud, and the ACFE’s data frames its scale: asset misappropriation, the group that includes payroll schemes, appears in 90 percent of occupational fraud cases 1 , and organizations with fewer than 100 employees suffer the highest median loss of any size band, $126,000, precisely because one person controls too much of the process. The classic scheme is the ghost employee: a fabricated or terminated worker kept on the payroll, with their pay routed to the fraudster. Others include padded hours or unauthorized overtime, inflated or invented commissions, unauthorized pay-rate changes, and advances or reimbursements that are never repaid. What they share is that the person committing the fraud has legitimate access to the payroll process and abuses it.

These schemes are quiet by nature, which is why they run so long. The ACFE consistently finds that occupational fraud is caught most often by a tip rather than by a control, and that many schemes continue for a year or more before discovery, because the person running them is also, often, the person who would notice. That is the structural weakness: when the same individual sets up employees, approves hours, and runs the payroll, there is no independent check on any of it. Internal payroll fraud is therefore not really a technology problem; it is a separation-of-duties problem, and the defenses that work are organizational, which is a different toolkit from the one that stops the external scam.

## The diversion scam: how a paycheck gets stolen from outside

External payroll fraud needs no insider and no access to your systems. In the standard version, a fraudster emails your HR or payroll department posing as an employee, often using a spoofed or compromised email address, and asks to update their direct-deposit information to a new bank account. Payroll makes what looks like a routine change, and the employee’s next paycheck, and every one after until someone notices, goes to the fraudster instead. It is a payee swap aimed at payroll, the same shape as the vendor and executive scams covered in the guide on [wire transfer fraud](https://rankshieldfinancial.com/resources/wire-transfer-fraud/), and the detailed mechanics are in the guide on [payroll diversion](https://rankshieldfinancial.com/resources/payroll-diversion-direct-deposit-scam/).

Two things make this scam effective and costly. First, the employer usually bears the loss, not the employee: the worker is still owed their wages, so the company typically has to pay them again while the diverted funds are gone, which means a stolen paycheck is a direct hit to the business. Second, self-service portals, often assumed to be a defense, do not stop it, because a fraudster who has phished an employee’s credentials can change the bank details through the portal exactly as the employee would, with no email to flag. Payroll diversion is a form of business email compromise, the category the FBI put at $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH 2 , and it is stopped not by better software alone but by verifying the change before the money moves.

## Why the two families need different controls

The reason it is worth insisting on the internal-versus-external split is that the controls do not transfer. Insider schemes are defeated by structure: separating the duties of setting up employees, approving hours and rates, and running the payroll so that no one person controls the whole chain; reviewing the payroll register and any roster or rate changes against independent records; reconciling headcount to HR; and auditing periodically, ideally with the anonymous reporting channel the ACFE identifies as the most common way these frauds surface. None of that touches the external scam, because the outsider is not on your roster and not in your approval chain; there is nothing internal to separate or audit.

External diversion is defeated by verification: confirming any change to an employee’s banking details out of band, through a channel the requester could not have controlled, before the changed account is paid. A callback to the employee on a known number, or an in-person confirmation, breaks the deception because the fraudster cannot answer the real employee’s phone. That control, in turn, does nothing about a ghost employee, who has real, verified bank details and is simply not a real worker. So the honest conclusion is that payroll fraud requires two defenses running at once: organizational controls against the insider, and out-of-band verification against the outsider. A business that has only one has closed only one door.

## The controls that close both doors

In practice the two defenses fit together into a payroll process that is hard to game and hard to deceive. On the internal side: separate the roles so the person who adds or changes an employee is not the person who approves the payroll run; review every new employee, every rate or commission change, and every banking-detail change against independent documentation before it takes effect; reconcile the payroll register to your headcount each cycle; and keep an anonymous reporting channel open, because tips remain the leading way insider schemes are caught. These steps make it structurally difficult for one person to pay out money that should not be paid.

On the external side, treat every change to an employee’s direct-deposit details as an event to verify, exactly as you would a vendor’s banking change. Confirm the change out of band with the employee on a number you already had, hold the first payment to the new account until that verification is complete, and keep a record that it happened. The overlap between the two defenses is the banking-detail change, which is both where an insider might route a ghost employee’s pay and where an outsider diverts a real one, which is why an independent verification of that specific change, with a named approver, protects against both at once. The general discipline is the same one described in the guide on [how to verify a payment change](https://rankshieldfinancial.com/resources/how-to-verify-wiring-instructions-bank-changes/).

## Where RankShield Financial fits, and where it does not

The honest framing matters especially here, because payroll fraud spans a part RankShield addresses and a part it does not. RankShield Financial does not audit timesheets, reconcile headcount, or detect a ghost employee; those are internal-control and audit functions, and a ghost employee with legitimate bank details is not something a payment-verification layer can see. What RankShield does is operate on the external side and the outbound payment: it verifies that a change to a payee’s banking details is genuine and that a named person approved it before the payroll payment settles, and it seals a checkable record. It is a verification and attestation layer in the payment authorization path, not a payroll system or a custodian of funds, and it never touches the money.

That makes RankShield a direct control against payroll diversion and a partial one against the insider scheme, at exactly the point the two families overlap: the banking-detail change and the release of the payment. When a direct-deposit change is verified out of band and a named approver is recorded before the run, the emailed diversion fails and an insider rerouting pay to a ghost account faces an independent check it cannot quietly clear. The boundaries stay explicit: RankShield verifies the payee and the approval and proves the decision; it does not replace your separation of duties, your payroll audit, or your HR reconciliation, and it is a design-partner-stage product that claims no network it has not built. If you want that verification in front of your payroll payments, you can [see how it works](https://rankshieldfinancial.com/how-it-works/) or [request access](https://rankshieldfinancial.com/contact/).

## What to do about payroll fraud

The practical takeaway is to defend both directions on purpose rather than assuming one control covers the other. For the insider risk, separate the duties of hiring, approving, and paying; review roster, rate, and commission changes against independent records; reconcile headcount each cycle; and keep an anonymous tip line, because that is how most of these are actually caught. For the external risk, verify every direct-deposit change out of band before the changed account is paid, hold the first payment to new details, record a named approver, and keep the evidence. The single highest-leverage step, because it sits where both families overlap, is to make an independent verification of any banking-detail change a required part of running payroll rather than a courtesy.

Payroll is a large, recurring, predictable payment, which is exactly what makes it worth attacking from both inside and out, and exactly why a single unverified change can bleed for months before anyone notices. Closing both doors is not about buying more software; it is about recognizing that the insider and the outsider are different adversaries who happen to target the same money, and building a process that answers each. Do that, and the payroll run stops being one of the easiest large payments in the business to compromise and becomes one of the best defended.
        Operate it
## Verify a payment before it settles

Compose a payment and the conditions around it, then run the same check the product runs on a live rail. The verdict comes back before the money would move.
      Pay to     Amount (USD)     Conditions around this payment      Bank details changed by email       First-time payee       Amount over approval policy       Approver signature verifies       PRE-SETTLEMENT VERDICT  RANKSHIELD NETWORK
Compose a payment on the left and run the check. The verdict is returned before the money moves, the way the product returns it on a live rail.

Sandbox demo · reproduces the product’s verdict logic and signing metadata · not a live network call
        Downloadable · SVG
Payroll fraud comes from two directions that need different controls. Insider schemes (ghost employees, padded hours, inflated commissions) are defeated by separation of duties, review, and audit. External diversion (a spoofed request to change an employee’s direct-deposit details) is stopped by verifying the banking change out of band before the payroll run. The two overlap at the banking-detail change and the payment’s release, so verifying that change with a named approver protects against both at once.
      FAQ
## Frequently asked questions

Every question buyers ask before they trust a payment-security platform, answered directly.
           JAMIE KLONCZ · RANKSHIELD FINANCIAL           ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.
      REQUEST ACCESS →           Self-check
## How exposed are your payments?

Five controls decide whether an authorized-payment scam gets through on a fast rail. Answer them honestly to see where you stand.

- 01 Do you send payments on instant or same-day rails (RTP, FedNow, same-day ACH)?
- 02 Can one person both change a vendor’s bank details and approve the payment?
- 03 Do you always confirm a bank-detail change on a number from your own files, not the request?
- 04 Is the first payment to a new or changed payee held for verification before it goes out?
- 05 Do you keep a signed record of exactly who approved each payment?

Answer all five to see where you stand · 0/5
        References
- [ACFE, Occupational Fraud 2026: A Report to the Nations (asset misappropriation, incl. payroll schemes, in 90% of cases; ~5% of revenue; under-100-employee orgs $126K, highest median; tips the leading detection method)](https://www.acfe.com/fraud-resources/report-to-the-nations)
- [FBI IC3, 2025 Internet Crime Report (business email compromise $3.046B; 86% of BEC money moved by wire or ACH)](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf)
- [Association for Financial Professionals, 2026 AFP Payments Fraud and Control Survey (76% of organizations faced attempted or actual payments fraud)](https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud)

         About the author
## [Jamie Kloncz](https://rankshieldfinancial.com/about/) Founder, RankShield Financial

Jamie founded RankShield Financial to verify a payment’s intent and authority before it settles on instant and tokenized rails. These guides are written from building that product and reading the primary sources directly: every statistic here links to its original filing or report, never a secondhand summary.

- Primary sources only: each figure links to the original filing
- Honest boundaries: what verification can and cannot do is stated plainly
- Last verified August 18, 2026

  How RankShield Financial verifies →  Request access →            Verify, then settle
## See your payments verified before they settle.

RankShield Financial is rolling out with design partners on instant and tokenized rails. Request access and we’ll map it to your settlement flow.
  Request access  How it works

## Frequently asked questions

### What is payroll fraud?

Payroll fraud is any scheme that causes an organization’s payroll to pay out money it should not, and it comes from two very different directions. Internal payroll fraud is committed by insiders who game the process, through a ghost employee kept on the payroll, padded hours or unauthorized overtime, inflated commissions, or unauthorized pay-rate changes. External payroll fraud, or payroll diversion, is committed by outsiders who deceive HR or payroll into changing a real employee’s direct-deposit details so the paycheck goes to the fraudster. The two are committed by different people and stopped by different controls: insider schemes by separation of duties and audit, external diversion by verifying banking changes out of band before payment. Treating them as one problem is why many businesses close one door and leave the other open.

### What is a ghost employee?

A ghost employee is a fabricated or terminated worker kept on the payroll so that their pay can be routed to the fraudster. The ghost may be entirely made up or a real former employee who was never removed after leaving, and the pay is directed to a bank account the fraudster controls. Ghost-employee schemes are a classic form of internal payroll fraud and are possible when one person controls too much of the process, setting up employees, approving hours, and running the payroll without an independent check. They are caught by separating those duties, reconciling the payroll register to actual headcount from HR, reviewing new-employee and banking-detail changes against independent records, and maintaining an anonymous tip line, since the ACFE finds tips are the most common way such schemes are discovered. A payment-verification tool cannot detect a ghost employee on its own, because the ghost’s bank details are real; this is an internal-controls problem.

### How does payroll diversion work?

Payroll diversion is a business email compromise scam aimed at payroll. A fraudster contacts your HR or payroll department, usually by a spoofed or compromised email, posing as an employee and asking to update their direct-deposit information to a new bank account. Payroll processes what looks like a routine change, and the employee’s next paycheck, and every one after until it is noticed, is deposited to the fraudster instead. The employer typically bears the loss, because the employee is still owed their wages and must be paid again while the diverted funds are gone. Self-service portals do not reliably stop it, because a fraudster who has phished an employee’s login can change the bank details through the portal just as the employee would. The defense is to verify any direct-deposit change out of band, by contacting the employee on a known number before the changed account is paid.

### Who is responsible when a paycheck is diverted to a fraudster?

In most cases the employer bears the loss, and this is general information rather than legal advice. Because the employee is still legally owed their wages, the company usually has to pay them again, while the money sent to the fraudster’s account is gone, so a diverted paycheck is typically a direct loss to the business rather than to the worker. Beyond the immediate loss there is exposure to employee trust and, depending on the facts, to claims about how the change was handled. This is why the verification burden belongs with the employer’s process: confirming any direct-deposit change out of band before paying the new account protects the company’s own money, not just the employee’s. Consult counsel for your specific situation, since liability depends on the facts and jurisdiction.

### How do you prevent payroll fraud?

By defending both directions, because one control does not cover the other. Against insider schemes: separate the duties of setting up employees, approving hours and rates, and running payroll so no one person controls the chain; review roster, rate, and commission changes against independent records; reconcile the payroll register to headcount each cycle; audit periodically; and keep an anonymous reporting channel, since tips catch most of these. Against external diversion: verify every change to an employee’s direct-deposit details out of band, by contacting the employee on a number you already had, before the changed account is paid, and hold the first payment until it is confirmed. The step where the two overlap is the banking-detail change, so making an independent verification of that change, with a named approver and a record, a required part of running payroll is the single highest-leverage control.
