Payroll fraud is one label for two genuinely different problems, and treating them as one is why businesses keep leaving a door open. The first kind comes from inside: an employee or manager games the payroll itself, through a ghost employee, padded hours, or an inflated commission. The second comes from outside: a fraudster diverts a real employee’s paycheck by changing the direct-deposit details, usually through a spoofed email to payroll or HR. These are committed by different people, exploit different weaknesses, and are stopped by different controls, so a business that hardens one while ignoring the other is still exposed. Internal payroll schemes fall under what the ACFE calls occupational fraud, where asset misappropriation appears in 90 percent of cases and the typical organization loses about 5 percent of revenue to fraud1. External diversion is a form of business email compromise, which the FBI put at $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH2. This guide separates the two families, explains how each works, and shows the controls that close both doors.
Two families of payroll fraud, and why the distinction matters
The single most useful thing to understand about payroll fraud is that it arrives from two directions, and the two have almost nothing in common except the word payroll. Internal payroll fraud is committed by people inside the organization, employees, managers, or whoever controls the payroll process, who manipulate it to pay out money that should not be paid, to themselves or an accomplice. External payroll fraud, usually called payroll diversion, is committed by outsiders who never touch your systems; they simply deceive your HR or payroll staff into sending a real employee’s pay to an account the fraudster controls. One is an abuse of trust from within; the other is a deception from without.
This distinction is not academic, because the two families are stopped by entirely different controls, and confusing them leaves a real gap. A business that installs strong separation of duties and audits its payroll register has hardened itself against the insider schemes, and may believe it has solved payroll fraud, while remaining completely open to an emailed direct-deposit change that reroutes a paycheck. The reverse is also true: a company that trains staff to verify banking changes has closed the external door while a ghost employee quietly draws a salary inside. Naming the two families is the first step, because you cannot close a door you have not noticed is there.
The insider schemes: how payroll gets gamed from within
Internal payroll fraud is a category of occupational fraud, and the ACFE’s data frames its scale: asset misappropriation, the group that includes payroll schemes, appears in 90 percent of occupational fraud cases1, and organizations with fewer than 100 employees suffer the highest median loss of any size band, $126,000, precisely because one person controls too much of the process. The classic scheme is the ghost employee: a fabricated or terminated worker kept on the payroll, with their pay routed to the fraudster. Others include padded hours or unauthorized overtime, inflated or invented commissions, unauthorized pay-rate changes, and advances or reimbursements that are never repaid. What they share is that the person committing the fraud has legitimate access to the payroll process and abuses it.
These schemes are quiet by nature, which is why they run so long. The ACFE consistently finds that occupational fraud is caught most often by a tip rather than by a control, and that many schemes continue for a year or more before discovery, because the person running them is also, often, the person who would notice. That is the structural weakness: when the same individual sets up employees, approves hours, and runs the payroll, there is no independent check on any of it. Internal payroll fraud is therefore not really a technology problem; it is a separation-of-duties problem, and the defenses that work are organizational, which is a different toolkit from the one that stops the external scam.
The diversion scam: how a paycheck gets stolen from outside
External payroll fraud needs no insider and no access to your systems. In the standard version, a fraudster emails your HR or payroll department posing as an employee, often using a spoofed or compromised email address, and asks to update their direct-deposit information to a new bank account. Payroll makes what looks like a routine change, and the employee’s next paycheck, and every one after until someone notices, goes to the fraudster instead. It is a payee swap aimed at payroll, the same shape as the vendor and executive scams covered in the guide on wire transfer fraud, and the detailed mechanics are in the guide on payroll diversion.
Two things make this scam effective and costly. First, the employer usually bears the loss, not the employee: the worker is still owed their wages, so the company typically has to pay them again while the diverted funds are gone, which means a stolen paycheck is a direct hit to the business. Second, self-service portals, often assumed to be a defense, do not stop it, because a fraudster who has phished an employee’s credentials can change the bank details through the portal exactly as the employee would, with no email to flag. Payroll diversion is a form of business email compromise, the category the FBI put at $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH2, and it is stopped not by better software alone but by verifying the change before the money moves.
Why the two families need different controls
The reason it is worth insisting on the internal-versus-external split is that the controls do not transfer. Insider schemes are defeated by structure: separating the duties of setting up employees, approving hours and rates, and running the payroll so that no one person controls the whole chain; reviewing the payroll register and any roster or rate changes against independent records; reconciling headcount to HR; and auditing periodically, ideally with the anonymous reporting channel the ACFE identifies as the most common way these frauds surface. None of that touches the external scam, because the outsider is not on your roster and not in your approval chain; there is nothing internal to separate or audit.
External diversion is defeated by verification: confirming any change to an employee’s banking details out of band, through a channel the requester could not have controlled, before the changed account is paid. A callback to the employee on a known number, or an in-person confirmation, breaks the deception because the fraudster cannot answer the real employee’s phone. That control, in turn, does nothing about a ghost employee, who has real, verified bank details and is simply not a real worker. So the honest conclusion is that payroll fraud requires two defenses running at once: organizational controls against the insider, and out-of-band verification against the outsider. A business that has only one has closed only one door.
The controls that close both doors
In practice the two defenses fit together into a payroll process that is hard to game and hard to deceive. On the internal side: separate the roles so the person who adds or changes an employee is not the person who approves the payroll run; review every new employee, every rate or commission change, and every banking-detail change against independent documentation before it takes effect; reconcile the payroll register to your headcount each cycle; and keep an anonymous reporting channel open, because tips remain the leading way insider schemes are caught. These steps make it structurally difficult for one person to pay out money that should not be paid.
On the external side, treat every change to an employee’s direct-deposit details as an event to verify, exactly as you would a vendor’s banking change. Confirm the change out of band with the employee on a number you already had, hold the first payment to the new account until that verification is complete, and keep a record that it happened. The overlap between the two defenses is the banking-detail change, which is both where an insider might route a ghost employee’s pay and where an outsider diverts a real one, which is why an independent verification of that specific change, with a named approver, protects against both at once. The general discipline is the same one described in the guide on how to verify a payment change.
Where RankShield Financial fits, and where it does not
The honest framing matters especially here, because payroll fraud spans a part RankShield addresses and a part it does not. RankShield Financial does not audit timesheets, reconcile headcount, or detect a ghost employee; those are internal-control and audit functions, and a ghost employee with legitimate bank details is not something a payment-verification layer can see. What RankShield does is operate on the external side and the outbound payment: it verifies that a change to a payee’s banking details is genuine and that a named person approved it before the payroll payment settles, and it seals a checkable record. It is a verification and attestation layer in the payment authorization path, not a payroll system or a custodian of funds, and it never touches the money.
That makes RankShield a direct control against payroll diversion and a partial one against the insider scheme, at exactly the point the two families overlap: the banking-detail change and the release of the payment. When a direct-deposit change is verified out of band and a named approver is recorded before the run, the emailed diversion fails and an insider rerouting pay to a ghost account faces an independent check it cannot quietly clear. The boundaries stay explicit: RankShield verifies the payee and the approval and proves the decision; it does not replace your separation of duties, your payroll audit, or your HR reconciliation, and it is a design-partner-stage product that claims no network it has not built. If you want that verification in front of your payroll payments, you can see how it works or request access.
What to do about payroll fraud
The practical takeaway is to defend both directions on purpose rather than assuming one control covers the other. For the insider risk, separate the duties of hiring, approving, and paying; review roster, rate, and commission changes against independent records; reconcile headcount each cycle; and keep an anonymous tip line, because that is how most of these are actually caught. For the external risk, verify every direct-deposit change out of band before the changed account is paid, hold the first payment to new details, record a named approver, and keep the evidence. The single highest-leverage step, because it sits where both families overlap, is to make an independent verification of any banking-detail change a required part of running payroll rather than a courtesy.
Payroll is a large, recurring, predictable payment, which is exactly what makes it worth attacking from both inside and out, and exactly why a single unverified change can bleed for months before anyone notices. Closing both doors is not about buying more software; it is about recognizing that the insider and the outsider are different adversaries who happen to target the same money, and building a process that answers each. Do that, and the payroll run stops being one of the easiest large payments in the business to compromise and becomes one of the best defended.
