Watch out! Two new payroll email scams are about
Businesses are being warned about two new payroll email scams targeting busy employees during the festive season.
The first one, initially discovered in Ireland, identified that fraudsters were hacking into employees’ accounts and then sending the HR or payroll department seemingly legitimate emails. These emails ask that the employees’ wages or salaries be paid into a different bank account – the fraudsters'. These imposters rely on the hectic festive period to catch unsuspecting and busy staff off their guard and not carry out the appropriate checks.
Head of the Banking and Payments Federation Ireland, Olivia Buckley, warns businesses to be on the look out for sophisticated scams such as this one all year round, but particularly during the holidays: “December is a particularly busy period for many businesses with high volumes of transactions and payments being made to meet Christmas and year-end deadlines.” She goes on to warn that instances of payroll scams are on the rise with the criminals targeting HR and payroll departments in order to defraud wages and salaries. She urges “businesses to verify all such emails with their employees verbally in advance of making any changes to payroll details.”
A second payroll scam
Research teams have also discovered a second scam involving the topic of payroll. This phishing campaign also uses emails to target unsuspecting employees but this time it does so by using seemingly legitimate subject lines about payroll to encourage the user to open the email.
Once opened, the message encourages the user to click on a link that sends them to a Google Doc which, in turn, contains further links which lead to malicious files containing downloaders of TrikBot, a Trojan that targets financial information. This fraudulent campaign is particularly sophisticated as it uses a legitimate email delivery service to send the attack emails and to hide the malicious links contained in the Google Doc.
How to protect your business from payroll scams
There are a number of ways you can protect your employees and your business from falling prey to malicious payroll emails, including:
- Use a filtering service that detects and blocks suspicious emails
- Verbally confirm any attempts to change payroll with employees
- Keep up to date with the latest payroll and scam email news
- Educate your employees about how to spot phishing emails
- Remove any unnecessary information from your website
- Install anti-virus software across all devices
At Essential Payroll, we take security seriously. By utilising our experience, investing in the latest technology and keeping up to date with payroll news, we ensure your business is protected when you outsource your payroll to us. To find out more, contact Essential Payroll today on 02382 023223.