“If I could sum up why I’m committed to the HR Girlfriends community it would come down to because we are ‘….in this together.'”

~Sana’ Rasul, Chief Girlfriend

Q&A: We’ve received suspicious emails that appear to be from employees asking to change their direct deposit information. What should we do?

This is likely a phishing scam – a type of con in which scammers use emails, texts, or phone calls to trick someone into providing company or personal information that then allows the scammer to steal from them. These messages often appear to come from someone the recipient knows – in this instance, your employees.

A successful scam can be a costly data breach with legal consequences for employers. In this case, had you fallen for the direct deposit scam, your employees would not have been paid on time, and you’d be out the money you owed them.

To protect your organization from this and other phishing attempts, we recommend taking the following steps:

• Verify that the message is not legitimate. In this case, inspect the email addresses for validity and reach out to the employees to confirm they didn’t request to have their bank information changed.
• Notify your IT department of the potential phishing attempt.
• Inform your workforce that scammers are afoot and remind them not to respond to emails that are suspicious or to email sensitive information. Email is like a postcard, potentially visible to anyone, so employees shouldn’t email their banking or other sensitive information.
• Work with your IT department to train employees how to recognize phishing attempts and what to do if they notice or fall prey to one.
• Ensure employees update their security software, internet browser, and operating system regularly.
• Create processes and policies that staff should follow in case of a breach, including what notices need to be given.

This Q&A does not constitute legal advice and does not address state or local law.

Answer from Sarah, PHR, SHRM-CP:
Sarah has extensive Human Resources experience in the legal, software, security and property preservation industries. She has a Business Communications degree from Villa Julie College (now Stevenson University) and a master’s certificate in Human Resources Management and a Strategic Organizational Leadership certification from Villa Nova University. Sarah is also a member of the National Society of Human Resources Management and has managed the HR function for small startup companies to mid-sized/large organizations.

Leave a comment

Never miss an opportunity to earn HRCI/SHRM credits, identify a mentor, or connect 1:1 with another HR Girlfriend in your city or across the country.

0 Comments
Inline Feedbacks
View all comments

HR Girlfriends™ is a Human Resources networking organization dedicated to advancing the practice and culture of people empowerment. Our team of Girlfriends consult, train, educate, develop, share, promote, and advocate for solutions in the field of human resource management.

Are You IN?
Or Are You OUT?

It’s time you join forces with a community of like-minded peers ready to tackle the issues unique to the women of HR.
  • All
  • Affirmation
  • Career Mondays
  • Certification
  • COVID-19
  • CyberSAFE
  • Guest Blogger
  • HR Advisor
  • HR Law Alert
  • HR Q&A
  • HR Reading
  • HR Reel Talk
  • Join Our Team - Apply Now
  • Membership
All
  • All
  • Affirmation
  • Career Mondays
  • Certification
  • COVID-19
  • CyberSAFE
  • Guest Blogger
  • HR Advisor
  • HR Law Alert
  • HR Q&A
  • HR Reading
  • HR Reel Talk
  • Join Our Team - Apply Now
  • Membership
Affirmation

Affirmation: 4 Important Life Skills Your Parents Didn’t Teach You

We learn a lot of things in school, but many of them aren’t particularly valuable from the standpoint of practicality. You were probably required to …

Read More →
Career Mondays

Career Monday: Save Your Job – How to Deal With a Bad Boss

Odds are that you will have at least one bad boss sooner or later. It can be a very challenging situation without obvious solutions. But …

Read More →
HR Q&A

Q&A: Exempt Employee Taking Long Lunches

You can deduct hours from this exempt employee’s PTO bank for time she was scheduled to work but didn’t work, but if it wasn’t made …

Read More →
Share via
Copy link
Powered by Social Snap