--- name: respond-to-a-payroll-fraud-incident category: money description: Respond to suspected payroll fraud by protecting employees, containing payment and access abuse, preserving evidence, reconciling beneficiaries, and securing the next payroll run. Use when payroll credentials, bank details, files, off-cycle payments, or employee identities may be compromised. --- # respond-to-a-payroll-fraud-incident Protect people's pay and safety while preserving the evidence needed to understand every transaction. ## When to use - Use for unauthorized bank-detail changes, ghost employees, altered pay, fraudulent off-cycle runs, compromised payroll accounts, or manipulated bank files. - Activate qualified payroll, banking, security, privacy, employment, legal, insurance, and law-enforcement support as appropriate. ## Preconditions - Establish an incident lead plus independent payroll, treasury, identity, security, HR, privacy, legal, communications, and country owners. - Use a clean communication channel and verify responders outside potentially compromised email, HR, payroll, or single-sign-on systems. - Define stop, recall, employee-support, evidence, next-run, regulatory, and communication authority. ## Procedure Run **employee protection and payment containment**, **access and evidence preservation**, **payroll and beneficiary reconciliation**, and **recovery and next-run control** as one coordinated incident process. 1. Open a **payroll fraud incident timeline** with detection, actors, accounts, sessions, files, approvals, bank events, employee changes, payments, decisions, evidence custody, and timestamps. 2. Protect employees first: identify pay at risk, establish safe contact and hardship support, and avoid exposing affected people or treating victims as suspects. 3. Contact banks and processors through known channels to stop pending files, freeze suspicious beneficiaries, recall or trace payments, and preserve transaction records. 4. Preserve logs, exports, bank files, payroll versions, approval records, email, identity events, endpoints, configuration, and timestamps before changing systems where safe. 5. Contain compromised sessions, tokens, devices, credentials, MFA enrollments, service accounts, integrations, privileged roles, and automation with documented authorization. 6. Build an **employee, payment, and access reconciliation** from the authoritative employee roster through gross-to-net calculation, approved bank details, payment instruction, beneficiary, bank outcome, ledger, and employee receipt. Give every original and replacement payment an immutable ID and explicit prepared, transmitted, accepted, pending, settled, recalled, returned, rejected, recovered, or unresolved state; link replacements to originals so later recovery cannot create an untracked duplicate. 7. Verify bank-detail and identity changes with employees through a clean independently sourced channel. Do not rely on contact details changed during the suspected period. 8. Separate unauthorized, duplicate, missing, misdirected, pending, rejected, settled, recovered, and legitimate payments. Do not rerun an entire file blindly. 9. Scope the intrusion through identity, administrator, device, email, integration, data export, approval, and persistence evidence. Preserve uncertainty where logs are incomplete. 10. Coordinate privacy, employment, banking, insurance, reporting, law-enforcement, and notification duties by jurisdiction while minimizing unnecessary personal data. 11. Prepare corrected payments with dual control, verified beneficiaries, unique run and payment identifiers, out-of-band approval, bank confirmation, and employee support. 12. Build the next payroll from reconciled employee and beneficiary state on clean systems. Restrict change windows and require independent review of new MFA, bank, employee, pay, and off-cycle changes. 13. Reconcile recoveries, replacement payments, fees, payroll liabilities, tax, bank, and ledger entries without erasing the original trail. 14. Test controls over identity recovery, privileged access, change notifications, segregation, bank files, anomaly detection, employee verification, and incident response. ## Failure plan - If the next payroll cannot be trusted, pause submission and activate approved emergency pay or manual-continuity procedures with full reconciliation. - If a bank cannot stop settled funds, continue trace and recovery while paying affected employees through a controlled replacement process. - If the clean contact path is uncertain, do not disclose sensitive details or accept beneficiary changes until identity is independently established. - If evidence conflicts, preserve all versions and keep the affected population broad until it can be narrowed safely. ## Worked example Payroll detects bank-account changes and off-cycle payments for employees in several countries after a payroll administrator account gained a new MFA method, while files were sent to banks, some payments settled, employee identities may be compromised, and the next payroll run is hours away. Responders use clean channels, stop pending instructions, preserve identity and payroll evidence, verify employees outside changed records, reconcile every beneficiary and bank outcome, issue controlled replacements, and prepare the next run from a clean independently reviewed state. ## Done - A payroll fraud incident timeline verifies detection, access, changes, payroll runs, bank instructions, containment, decisions, notifications, and evidence custody - An employee, payment, and access reconciliation proves roster, gross-to-net, beneficiary, approval, bank outcome, receipt, recovery, replacement, ledger, and unresolved status for every affected item - A containment, recovery, and control-effectiveness report demonstrates clean administration, employee protection, next-run controls, legal and privacy handling, financial reconciliation, and tested remediation