About this tool
Take apart a salary-account change request: lookalike domains, no-phone-calls excuses, cut-off timing and the money at risk.
Payroll redirect fraud is a business email compromise in which someone impersonating an employee asks HR or payroll to pay their salary into a different bank account. This page scores a request against the signals that define the pattern — a personal or lookalike sender domain, a Reply-To that points elsewhere, an excuse for avoiding a phone call, timing against the payroll cut-off, and an account in a name that is not the employee's — and estimates what one undetected cycle costs. It is a checking aid for payroll and HR teams, not a substitute for calling the employee on the number already in your records.
Open Payroll Redirect Phishing Anatomy on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Every excuse for avoiding a call to the stored number is treated as a red flag, because out-of-band voice verification is what defeats this fraud.
Account-name mismatch, cut-off timing and simultaneous contact-detail changes are scored alongside the header analysis.
Shows what one cycle of diverted salary costs across the affected employees, which is usually what gets a control approved.
It is a business email compromise where a fraudster poses as an employee and asks HR or payroll to change the bank account that salary is paid into. No malware is involved — the entire attack is a plausible email, and the loss is the salary itself, usually discovered only when the real employee reports the money never arrived.
Call the employee on the phone number already held in the HR system, not any number in the email, and confirm the change verbally. Require the request to be submitted through the HR self-service portal where one exists, and send a change notification to the previously stored email and phone so the real employee hears about it.
Not necessarily. A compromised mailbox sends genuinely internal mail that passes every authentication check, and attackers often set an inbox rule to hide the replies. Sender domain matching your own lowers the odds of a spoof but does not replace the voice check.
Sometimes, if you act immediately. Tell your bank the same day and ask for a recall or an indemnity claim while the funds may still be sitting in the receiving account; once withdrawn or moved on, recovery becomes unlikely. Report it to your national fraud reporting body and your insurer as well — this is general information, not legal advice.