The FBI issued a public service announcement (PSA) encouraging employers to remind employees not to respond to phishing emails from cybercriminals who want access to employees’ payroll information [FBI, Alert No. I-091818-PSA, 9-18-18].
How the Scam Works
The FBI said that cybercriminals are targeting employees through phishing emails designed to capture an employee’s login credentials to his or her employer’s self-service application. Once they obtain the login credentials, cybercriminals can change the bank account information to which the employee’s paycheck is deposited. The cybercriminals also change the alert settings so employees are not informed of the direct deposit changes.
How Employers Can Help
The FBI recommends employers:
How to Report Suspicious Activity
The FBI encourages victims to report suspicious or criminal activity to their local FBI field office, and file a complaint with the Internet Crime Complaint Center (note “payroll diversion” in the body of the complaint).
To learn more about federal and state laws, regulations, and information to keep your company's payroll operations in compliance, check out Payroll Source Plus!