{
  "slug": "payroll-diversion-direct-deposit",
  "title": "The direct deposit change is the whole attack",
  "summary": "Payroll diversion needs no malware, just one profile edit. Why alerts, callbacks and MFA miss it, and the control that stops it at the change endpoint.",
  "lede": "Payroll diversion does not require malware, a zero day, or a clever exploit. It requires one form submission in a system the attacker is legitimately logged into. Every control most employers have bought sits in the channel the attacker already owns, which is why the money is gone before anyone knows a control was tested.",
  "date": "2026-09-04",
  "reading_time": "17 min read",
  "category": "Fraud",
  "tags": [
    "payroll diversion",
    "direct deposit fraud",
    "business email compromise",
    "HRIS security",
    "Storm-2657",
    "payroll fraud",
    "account takeover"
  ],
  "image": "https://cdn.twc.sh/images/igcache/Payroll%20Diversion%20Fraud/1200_630/blog.jpg",
  "url": "/blog/payroll-diversion-direct-deposit.html",
  "wordcount": 4242,
  "related": [
    "vendor-bank-change-fraud",
    "help-desk-mfa-reset-attack",
    "session-theft-aitm"
  ],
  "schema": "Article"
}