When someone steals money from you, the damage is not always limited to the missing funds. Sometimes the most frustrating part is discovering how easily someone was able to pretend to be you and make important changes without your knowledge.
One Illinois employee shared a stressful situation after discovering that two of his paychecks had been redirected to a stranger’s bank account. The person behind it allegedly used his identity, contacted his workplace, and managed to change his direct deposit information without his approval.
Now he is trying to understand what responsibilities his employer has, what records he can request, and what steps he should take to protect himself. With wages involved and questions surrounding identity theft, he turned to Reddit for guidance. Scroll down to see what advice others gave him.
A worker discovers a scammer impersonated him to HR and redirected two paychecks, leaving him fighting to recover his wages

![Scammer Pretends To Be Employee And Steals Two Paychecks Through A Fake HR Request '[Illinois] Someone impersonated me to HR, changed my direct deposit, and stole two paychecks'](https://dailyhighlight.com/wp-content/uploads/2026/09/wp-editor-1789701666758-1.webp)




































Few things create a stronger sense of vulnerability than realizing something important was taken from you without your knowledge. A paycheck is not just money. It represents time, effort, and the agreement between a person and their employer.
In this situation, the OP was not only dealing with missing wages but also with the unsettling realization that someone successfully pretended to be them and changed a major financial detail without their consent.
The emotional weight of this story comes from the loss of control. The OP appears less focused on blaming one individual and more concerned about understanding how the system allowed this to happen. Someone accessed enough information to imitate an employee, submit fraudulent paperwork, and redirect two weeks of earnings.
The frustration is understandable because the problem was not caused by a normal banking mistake; it was a breakdown of trust and verification. Even the HR comment about checking the account may have felt dismissive because it shifted attention toward the victim’s reaction rather than the unauthorized action itself.
There is another perspective worth considering. Payroll fraud cases often reveal a difficult reality about modern workplaces: many security failures happen through ordinary human processes rather than advanced technology. Employees, HR departments, and payroll providers are all balancing convenience with security.
A request that appears routine, such as changing direct deposit information, can become dangerous if identity verification steps are too weak. The lesson is not simply that one person made a mistake, but that systems need safeguards against impersonation.
Cybersecurity psychologist Dr. Mary Aiken, who studies the relationship between humans and technology, has explained that many digital crimes succeed because attackers exploit human behavior, trust, and routine processes rather than relying only on technical methods.
She emphasizes that cybersecurity is also a human issue because people make decisions within systems that are often designed around speed and convenience.
This insight helps explain why the OP’s response has been focused on documentation.
Requesting records, preserving communication, confirming what information was shared, and creating a written timeline are reasonable steps after an identity-related incident. Documentation helps separate facts from assumptions and gives everyone involved a clearer path toward resolving the problem.
The situation also highlights why employees should not feel responsible for preventing every type of fraud alone. People may monitor their accounts carefully and still become victims when someone else successfully impersonates them.
At the same time, incidents like this show the importance of personal financial monitoring, credit freezes when appropriate, and asking employers what verification procedures are used for sensitive changes.
Ultimately, the biggest issue is not only the missing paychecks. It is the question of how trust can be rebuilt after someone’s identity was used against them. A secure workplace is not one where mistakes never happen; it is one where problems are taken seriously, investigated carefully, and corrected transparently.
Here’s what people had to say to OP:
These commenters agreed that the employer is responsible for paying OP because the company was the victim of the payroll scam






















These Redditors criticized the company’s security process, saying HR should have verified the payment change request before approving it

























This group recommended documenting the incident, checking records carefully, and obtaining official reports or proof related to the fraud






Should companies always immediately replace wages lost through an internal verification failure, or should employees wait until fraud investigations are complete? Have you or someone you know experienced a payroll scam before?














