Most cross-border payment fraud is not a technical breach. It is someone impersonating an executive or a supplier and persuading a member of staff to authorise a transfer. That is business email compromise, and it works because the request looks legitimate and the person receiving it has no easy way to check. Payroll is a particular target, because the payments are large, regular and routine enough that an unusual one can pass unnoticed.
The controls that stop it are unglamorous: verification out of band, multi-factor authentication, and limiting who can change bank details. Last updated September 2026.
| Attack | How it works | What stops it |
|---|---|---|
| Business email compromise | Impersonated executive requests a transfer | Verify by a second channel, always |
| Supplier bank change | Fake notice of new account details | Call the known number, not the one in the email |
| Payroll diversion | Employee bank details altered before payday | Change controls and confirmation to the employee |
| Phishing | Credentials harvested, then used | MFA, so credentials alone are not enough |
| Deepfake authorisation | Cloned voice or video approves a payment | Never authorise on a single verbal instruction |
Cross-border payments are a natural target. The amounts are large, the recipients are unfamiliar, and the people approving them are often working across time zones without an easy way to check a request in person.
The Federal Trade Commission reported that consumers alone lost more than $12.5 billion to fraud in 2024, a sharp rise on the previous year. Business losses are reported separately and are not in that figure, but the trend is the same and the techniques overlap.
The case worth knowing is Orion S.A., which lost approximately $60 million in August 2024 after an employee was deceived into making a series of wire transfers. No system was hacked. A person was convinced.
Every country has its own rules on payments, tax and reporting. When your finance team is reconciling several jurisdictions, an unusual transaction looks less unusual. Fraud often surfaces weeks later during reconciliation rather than at the moment it happens.
When approvals travel by email between people in different time zones who rarely meet, the informal checks that catch fraud in a single office are missing. Someone cannot walk over and ask.
Payroll runs are substantial, regular and expected. That is precisely what makes an inserted or altered payment hard to spot.
This is one reason payroll data security matters as much as payment security. We cover the wider picture in common payroll processing challenges and how to pay a global workforce.
The single most effective control. Any request to move money or change bank details gets confirmed by a different route than the one it arrived on, using a number you already hold rather than one in the message.
This stops business email compromise regardless of how convincing the email is, and it stops deepfake voice requests too.
Most payroll diversion starts with an altered account number. Require confirmation directly with the employee, restrict who can make the change, and log every one.
Stolen credentials are common and cheap. MFA means they are not sufficient on their own.
Not generic security awareness. Show your finance and HR teams real examples of executive impersonation, urgency pressure and supplier change requests, because those are what they will actually receive.
Automated detection that flags unusual payees, amounts or timing before a payment clears rather than after.
Review payment systems, payroll processes and access permissions on a schedule. Access accumulates quietly as people change roles, and dormant permissions are a common route in.
Whether a provider owns its entities or works through local partners also affects who is handling your money, which we cover in EOR operating models.
For more on evaluating providers: how to choose the right global payroll software.
Our data security and privacy standards cover the payroll platform end to end.
We run global payroll and act as Employer of Record across 214 countries and territories, with the controls above applied to every payment.
An attacker impersonates an executive, supplier or colleague by email and requests a payment or a change of bank details. There is usually no technical intrusion at all. It works through authority and urgency, which is why technical controls alone do not stop it.
Confirm it through a different channel than the one it arrived on, using contact details you already hold rather than any supplied in the message. If an email asks for a transfer, phone the person on their known number. This single habit prevents most of these attacks.
Yes. Voice cloning and video are now used to impersonate executives authorising transfers, and the quality is good enough that recognising the voice is not sufficient verification. Treat a verbal instruction as a request to be confirmed, not as an authorisation.
An attacker changes an employee's bank details shortly before payday so the salary is paid to an account they control. The employee reports not being paid, by which point the money has gone. Controlling who can change bank details, and confirming changes with the employee, is the defence.
Usually the business that authorised it, since the payment was technically legitimate. Banks are rarely obliged to reimburse authorised push payments, though rules differ by country. This is why prevention matters more than recovery.
It can, because payments run through established local banking relationships with verification built into the process, rather than ad hoc transfers to accounts your team has not paid before. It does not remove the need for your own controls on requests that originate inside your company.