Microsoft Warns of Hackers Compromising Employee Accounts to Steal Salary Payments
Microsoft Threat Intelligence has identified a financially motivated threat actor, designated as Storm-2657, responsible for executing "payroll pirate" attacks targeting universities and other organizations in the United States. These attacks involve the…
Microsoft Threat Intelligence has identified a financially motivated threat actor, designated as Storm-2657, responsible for executing "payroll pirate" attacks targeting universities and other organizations in the United States. These attacks involve the compromise of employee accounts to gain unauthorized access to human resources systems, redirecting salary payments to bank accounts controlled by the attackers.
The threat actor has been particularly active in the higher education sector, exploiting employee access to third-party Software as a Service (SaaS) platforms such as Workday. Since March 2025, Microsoft researchers have documented 11 successfully compromised accounts at three universities, which were subsequently used to launch phishing campaigns targeting approximately 6,000 email accounts across 25 educational institutions.
The attacks commence with carefully crafted phishing emails designed to harvest credentials using adversary-in-the-middle (AITM) phishing techniques. These emails exploit various social engineering themes, including fake campus illness outbreaks, with subject lines such as "COVID-Like Case Reported — Check Your Contact Status" and "Confirmed Case of Communicable Illness." Attackers impersonate legitimate university communications to enhance credibility.
Microsoft analysts identified that Storm-2657 exploits the absence of phishing-resistant multifactor authentication (MFA) in organizations, enabling them to intercept and use stolen MFA codes to access Exchange Online accounts. Once inside, the threat actors demonstrate persistence and stealth capabilities.
The attacks commence with carefully crafted phishing emails designed to harvest credentials using adversary-in-the-middle (AITM) phishing techniques.
Technical Infiltration and Persistence Mechanisms
Upon gaining access to victim accounts, the attackers establish persistence by enrolling their own phone numbers as MFA devices within compromised Workday profiles or Duo MFA settings. This allows continued access without requiring further MFA approval from legitimate users. The attackers also create sophisticated inbox rules to automatically delete or hide notification emails from Workday, ensuring victims remain unaware of unauthorized changes to their payroll configurations.
The threat actors utilize single sign-on (SSO) authentication to access Workday and methodically alter victims' salary payment configurations. These activities are recorded in Workday audit logs as "Change My Account" or "Manage Payment Elections" events, providing forensic evidence of unauthorized modifications.
Microsoft Defender for Cloud Apps can correlate these activities across Microsoft Exchange Online and third-party SaaS applications like Workday, facilitating the detection of suspicious cross-platform activities. The attack methodology emphasizes minimizing detection while maximizing financial impact, leveraging legitimate authentication mechanisms and automated email deletion to conceal evidence.
Based on reporting by Cyber Security News.
