Direct Deposit Fraud is Real—and Evolving Featured Image

Here’s How to Protect Yourself

Direct deposit scams and fraud are on the rise—and they’re not going away anytime soon. Scammers are getting smarter, faster, and more convincing. As a business owner or payroll admin, it’s critical to stay one step ahead to protect your team’s paychecks.

At Paper Trails, we’ve seen an increase in fraud attempts across our client base, and unfortunately, even successful breaches when scammers get access to employee email accounts. This isn’t just an isolved-specific issue, it’s a global cybersecurity crisis. And while isolved and our team are working constantly to enhance security features, every employer needs to understand how these scams happen and what you can do to stop them.

How direct deposit scams work

Here are the most common scenarios we’re seeing:

1. A company or payroll provider receives an email, allegedly from an employee, asking them to change their direct deposit. The form might look legitimate—even using your company’s official format. But the account is being changed to belong to a fraudster. Come payday, the money is gone, and the real employee never saw a cent.

This can happen even if the email request appears to come from the employee’s actual email address. In many cases, their email account was hacked due to reused or weak passwords.

2. Earlier this year, over 16 billion usernames and passwords were leaked onto the internet, the largest credential breach ever recorded. If employees use the same password for multiple accounts (email, banking, payroll), hackers can easily access their inboxes and even platforms like isolved.

Once in the email inbox, a scammer can:

  • Find payroll-related emails and pay stub alerts
  • Attempt to log into isolved using the same email password
  • If isolved MFA is set to email, they simply intercept the verification code and gain access

3. Phishing, vishing, and pharming attacks
In addition to email hacks, we are now seeing sophisticated phishing and pharming scams targeting payroll logins:

  • Phishing emails are sent to employees, asking them to click a link to “log in to isolved” to view a pay stub or resolve an issue. The link leads to a fake login page that looks identical to the real site.
  • Pharming happens when an employee searches “isolved login” in Google or another search engine, and hackers have paid for ads or used SEO tricks to put a fake login site at the top of the results. The URL is close to the real one but not exact (e.g., www.loginmyisolved.com instead of https://papertrails.myisolved.com).
  • Once the user enters their real credentials, the scammers capture them, immediately log into the real isolved site from another location, and trigger a two-factor authentication (2FA) code. The fake site prompts the user to enter this code, which the attacker then uses to complete the login and change direct deposit details.

Signs this may have happened:

  • The employee receives both a “Direct Deposit Change” email and a “Suspicious Login Attempt” email but ignores them.
  • The employee is redirected to the real iSolve site after logging in, making them think nothing unusual happened.