HR and payroll data leak: how to protect your pay and your identity

Breach / exposure. Updated 2026-09-13. About 5 minutes to read.

Protect your payroll login with a passkey or number-matching app, check your bank details in the HR portal every pay cycle, and get a tax identity PIN or protection from your tax office.

Your employer's HR and payroll systems hold a complete identity kit: your tax number, bank account, date of birth, home address and salary, and often passport or visa copies and medical leave notes. When that data leaks, criminals do not need anything else to impersonate you.

It goes wrong in two ways. A payroll provider can be breached in bulk, as happened when the MOVEit hack reached UK payroll firm Zellis in 2023. Or criminals can take over your own payroll login and quietly redirect your pay, a tactic Microsoft documented in 2025 and called payroll pirate attacks. This guide covers both.

Two real patterns: bulk breaches and payroll pirates

In June 2023 the BBC reported that criminals exploiting the MOVEit file transfer tool had stolen data from Zellis, a payroll provider, affecting eight of its client companies. BBC staff were told staff ID numbers, dates of birth, home addresses and National Insurance numbers were taken, and some British Airways staff were warned their bank details may have been stolen.

In October 2025 Microsoft described a group it tracks as Storm-2657 targeting US universities. The group sent HR-themed phishing emails, stole multi-factor codes through fake login pages, then logged in to Workday profiles and changed salary payment details to its own accounts. Since March 2025 Microsoft had seen 11 compromised accounts at three universities used to send phishing to nearly 6,000 email accounts across 25 universities. Microsoft stressed this was not a flaw in Workday, and that any HR platform could be targeted the same way.

The attackers created inbox rules that deleted Workday's warning emails, so victims never saw the notice that their bank details had changed. Some rule names were just dots or symbols to avoid attention.

What leaked HR data lets criminals do

  • File a fake tax return in your name and collect the refund.
  • Open credit, phone or buy-now-pay-later accounts using your tax number, date of birth and address.
  • Set up fraudulent direct debits from your bank account using your account details.
  • Target your pension, 401(k) or superannuation account with password resets.
  • Send convincing phishing about pay rises, bonuses, benefits enrolment or tax forms.
  • Use passport or visa copies to pass identity checks elsewhere.

First steps after your employer or payroll provider is breached

  1. Confirm the breach with HR through a channel you already know, such as the intranet or a phone number from your contract, not by replying to the notice email.
  2. Ask which fields about you were exposed: tax number, bank account, date of birth, identity documents, medical or leave records.
  3. Enrol in any monitoring offered by typing the provider's address yourself.
  4. United States: freeze your credit at Equifax, Experian and TransUnion if your Social Security number was included.
  5. United Kingdom: check your credit files with Experian, Equifax and TransUnion, and consider Cifas Protective Registration if identity documents were exposed.
  6. Australia: call IDCARE on 1800 595 160 for a free response plan, and ask the credit reporting bodies about a ban period if you see signs of misuse.
  7. Turn on transaction alerts with your bank and check for new direct debits or payees.

Protect your pay and your payroll login

  1. Open your payroll or HR portal from a bookmark or by typing its address, never from a link in an email.
  2. Change the password to a unique one and add the strongest sign-in method your employer allows, ideally a passkey, security key or an app that asks you to match a number.
  3. Check your bank details, personal email and phone number in the portal, and do it again after each pay run for the next few months.
  4. Never approve a sign-in prompt or read out a code you did not ask for, even if the caller says they are from IT or payroll.
  5. Make sure you still receive payroll notification emails. If they stop arriving, check your mailbox rules or ask IT to check them.
  6. Report emails about compensation updates, benefits enrolment or tax documents to your IT or security team before you open links.

Tax, pension and government accounts

  • United States: get an IRS Identity Protection PIN, a six-digit number that stops anyone else filing a tax return with your Social Security number. The IRS lets you get one proactively. Add strong sign-in to your 401(k) account.
  • Australia: if your tax file number was exposed, phone the ATO's Client Identity Support Centre on 1800 467 033, 8 am to 6 pm AEDT, Monday to Friday. The ATO can add protective measures to your record. Use a strong myID and check your super fund's contact and bank details.
  • United Kingdom: sign in to your HMRC personal tax account and check for employment or income records you do not recognise, and report suspected misuse of your National Insurance number to HMRC.

Your rights and who regulates it

  • United States: employers and payroll providers must notify you under state breach laws. Report identity theft at IdentityTheft.gov, and you can complain to your state attorney general.
  • Australia: serious breaches fall under the OAIC's Notifiable Data Breaches scheme. Private sector employers have an employee records exemption under the Privacy Act, which can limit complaints about your own employer, but a payroll provider holding the data may still be covered, and public sector employers fall under their own privacy laws.
  • United Kingdom: your employer is responsible for your data even when a provider like Zellis processes it. Complain to the employer first, then to the ICO.

Frequently asked questions

Someone changed my direct deposit details. What do I do?

Tell payroll immediately so they can stop or reverse the payment, then call your bank. Reset your HR and email passwords, remove any sign-in methods you did not add, check your mailbox rules and report it to police or IdentityTheft.gov.

Should I change my bank account after a payroll leak?

Not usually. Ask your bank to watch the account and turn on alerts. Open a new account if unauthorised debits appear or your bank recommends it. In the UK, the Direct Debit Guarantee covers refunds for debits you did not authorise.

Is it safe to click the link in my employer's breach notice?

Go to the source instead. Type the monitoring provider's address yourself or check the notice on your company intranet, because criminals copy breach letters within days.

Can I be affected if I left the company years ago?

Yes. HR systems often keep former staff records for years. Treat a notice about an old employer as seriously as one about your current job.

Tools that help

Related guides

Sources