Skip to main content Skip to footer

Protecting payroll when the client isn't who they claim to be

Most fraud prevention focuses on the mechanics of verifying identities, validating documents, and confirming payment instructions. However, what happens when every one of those checks passes, and the fraud is the client relationship itself?

That was the reality one staffing and workforce solutions company faced when a threat actor impersonated a legitimate business so convincingly that it established an entirely fraudulent client relationship – one that looked, sounded, and documented like the real thing. When the company recognized something wasn't adding up, it turned to its payroll and HR partner Adams Keegan, whose senior leadership was on the phone within minutes.

The Challenge

This was not a case of fraudulent payroll instructions or a single falsified document. It was a sophisticated business impersonation scheme in which an unknown threat actor assumed the identity of a real, legitimate company and built what appeared to be a true client engagement.

What made the scheme so difficult to detect is precisely what should give other business leaders pause:

  • The people were real. Contract workers were onboarded and completed standard identity verification, including I-9 verification, with documentation that was legitimate.

  • The impersonated business was real, an actual company that was itself a victim of the identity impersonation.

  • The relationship was the fraud. Believing it was working directly with a legitimate client, the company established the relationship, onboarded workers, and processed payroll under normal operating procedures.

  • Every signal looked normal. Communications, documentation, and requests were consistent with routine business operations and bypassed traditional fraud indicators, while the attacker quietly directed payroll to bank accounts under their control.

No outside party raised the alarm; the company began pulling the thread on its own. The supposed client failed to pay outstanding invoices, then claimed a wire had been sent – even producing what appeared to be a bank wire transfer document. However, the funds never arrived.

As the company worked to resolve the payment issue and verify what was actually happening, its team ultimately traveled to the physical location of the business it believed it had been working with. After multiple attempts, they reached the actual business owner in person, who confirmed he had no knowledge of the relationship and that his company was being impersonated. It was the company's own persistence, not an external warning, that uncovered the truth. This raises the unsettling question every leader should ask: Could this happen to us?

The Adams Keegan Solution

When the company realized what had happened, Gene Fidell answered the call right away, and within approximately 10 minutes a C-level Adams Keegan executive was conferenced into the conversation to help think through next steps. That level of responsiveness, paired with direct access to senior leadership in the first minutes of a crisis, was decisive, and it reflects exactly the kind of partnership the company was looking for when it chose a firm of Adams Keegan's size and service model over a large national payroll provider.

Adams Keegan moved immediately to help the company develop a clear plan of action and to execute the steps within its control:

  • Helping the company think through and structure its response in real time.

  • Processing check reversals for payroll payments that had already gone out.

  • Identifying one paper payroll check before it was deposited, allowing those funds to be recovered.

In parallel, the company's internal team led its own critical response efforts: working directly with financial institutions to pursue recovery, notifying law enforcement and its insurance carrier, preserving emails, payment records, and electronic evidence, tracing payroll and banking activity, and traveling in person to independently verify the impersonation with the legitimate business owner.

The Results

The response limited further exposure and strengthened the company's defenses going forward, but the outcome also underscores how damaging these schemes can be even when a victim acts quickly.

  • The incident was contained, with a clearly documented scope.

  • Enhanced business verification controls were implemented for future client onboarding.

  • Fraud awareness and risk management were strengthened across the organization.

Key Takeaway

This incident demonstrates that sophisticated fraud increasingly targets the trust of the business relationship itself, not just payroll or onboarding mechanics. Even when workers complete identity verification and documentation appears authentic, an organization can be exposed if an attacker has successfully impersonated the client requesting the work. Several lessons stand out:

  • Verify the relationship, not just the paperwork. Independent verification of new business relationships, authorized representatives, and payment instructions, through trusted, out-of-band channels, is a critical layer of protection.

  • Trust your instincts and keep pulling the thread. When something doesn't add up, persistent, independent verification can surface a problem no routine control would catch.

  • Understand your insurance coverage before you need it. Coverage for social engineering, financial crimes fraud, and cyber liability can be essential when prevention fails. Organizations should confirm what their policies actually cover well before an incident occurs.

  • Responsiveness matters in a crisis. When fraud occurs, immediate access to experienced, senior-level advisors can shape the speed and effectiveness of the entire response.

Posted: 

By: 

Adams Keegan

In Category: 

We use cookies to improve user experience and analyze website traffic. By clicking “Accept“, you agree to our website's cookie use as described in our Privacy Policy.