Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Exploit Microsoft Employee Accounts in Salary Theft Scheme

## Cybersecurity: Payroll Attack Incidents and Mitigations

Cybersecurity: Payroll Attack Incidents and Mitigations

Microsoft Threat Intelligence has identified an increase in sophisticated "payroll pirate" attacks. These attacks involve financially motivated actors hijacking employee accounts to redirect salary payments to attacker-controlled bank accounts.

In early 2025, threat actor Storm-2657 executed a phishing campaign targeting university staff, acquiring credentials and multi-factor authentication (MFA) codes. The attackers used realistic emails related to campus health issues or faculty misconduct to direct victims to phishing domains via Google Docs links.

Storm-2657 targeted U.S. higher education institutions by compromising third-party HR software-as-a-service (SaaS) platforms, such as Workday, to manipulate payroll settings and divert wages.

Eleven employee accounts across three universities were compromised. Over 6,000 phishing emails were sent to 25 institutions. Phishing-resistant MFA was absent in many cases, allowing attackers to intercept codes and bypass account protections.

Attackers disabled warning emails from Workday by creating inbox rules to delete notifications of profile changes. This allowed them to modify salary payment settings and redirect paychecks to their accounts. Approximately 10% of recipients recognized the emails as phishing attempts.

Microsoft Threat Intelligence has identified an increase in sophisticated "payroll pirate" attacks.
Amanda Parks · Thehackingpost

Storm-2657 enrolled personal phone numbers as MFA devices, eliminating the need for further approvals from compromised users.

Microsoft has provided affected customers with detailed tactics, techniques, and procedures (TTPs) to aid in incident response. Organizations are advised to implement phishing-resistant MFA, such as FIDO2 security keys or Windows Hello for Business, particularly for privileged and HR-facing roles, to reduce account takeover risks.

For detection, Microsoft Defender for Cloud Apps can identify suspicious inbox rule creations and payroll configuration changes by correlating signals from Exchange Online and Workday.

Compromised organizations should take the following steps:

Advertisement

Reset credentials and revoke sessions. Remove unauthorized inbox rules. Review and re-register or remove suspicious MFA devices. Revert any unauthorized payroll or bank account changes.

Enabling the Workday connector in Defender for Cloud Apps and deploying Threat Intelligence mapping analytics in Sentinel are recommended to automate monitoring of malicious domains and behavioral patterns.

In conclusion, adopting passwordless, phishing-resistant authentication and utilizing advanced detection capabilities are essential for protecting user accounts and securing employee compensation against evolving "payroll pirate" schemes.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories