Hackers Exploit Microsoft Employee Accounts in Salary Theft Scheme
## Cybersecurity: Payroll Attack Incidents and Mitigations
Cybersecurity: Payroll Attack Incidents and Mitigations
Microsoft Threat Intelligence has identified an increase in sophisticated "payroll pirate" attacks. These attacks involve financially motivated actors hijacking employee accounts to redirect salary payments to attacker-controlled bank accounts.
In early 2025, threat actor Storm-2657 executed a phishing campaign targeting university staff, acquiring credentials and multi-factor authentication (MFA) codes. The attackers used realistic emails related to campus health issues or faculty misconduct to direct victims to phishing domains via Google Docs links.
Storm-2657 targeted U.S. higher education institutions by compromising third-party HR software-as-a-service (SaaS) platforms, such as Workday, to manipulate payroll settings and divert wages.
Eleven employee accounts across three universities were compromised. Over 6,000 phishing emails were sent to 25 institutions. Phishing-resistant MFA was absent in many cases, allowing attackers to intercept codes and bypass account protections.
Attackers disabled warning emails from Workday by creating inbox rules to delete notifications of profile changes. This allowed them to modify salary payment settings and redirect paychecks to their accounts. Approximately 10% of recipients recognized the emails as phishing attempts.
Microsoft Threat Intelligence has identified an increase in sophisticated "payroll pirate" attacks.
Storm-2657 enrolled personal phone numbers as MFA devices, eliminating the need for further approvals from compromised users.
Microsoft has provided affected customers with detailed tactics, techniques, and procedures (TTPs) to aid in incident response. Organizations are advised to implement phishing-resistant MFA, such as FIDO2 security keys or Windows Hello for Business, particularly for privileged and HR-facing roles, to reduce account takeover risks.
For detection, Microsoft Defender for Cloud Apps can identify suspicious inbox rule creations and payroll configuration changes by correlating signals from Exchange Online and Workday.
Compromised organizations should take the following steps:
Reset credentials and revoke sessions. Remove unauthorized inbox rules. Review and re-register or remove suspicious MFA devices. Revert any unauthorized payroll or bank account changes.
Enabling the Workday connector in Defender for Cloud Apps and deploying Threat Intelligence mapping analytics in Sentinel are recommended to automate monitoring of malicious domains and behavioral patterns.
In conclusion, adopting passwordless, phishing-resistant authentication and utilizing advanced detection capabilities are essential for protecting user accounts and securing employee compensation against evolving "payroll pirate" schemes.
Based on reporting by GBHackers.
