Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Samsung showed me its secret HDR10+ Advanced TV samples – and I’m almost sold

    November 8, 2025

    Starbucks barista’s side hustle brings in $1 million a month

    November 8, 2025

    A new Chinese AI model claims to outperform GPT-5 and Sonnet 4.5 – and it’s free

    November 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Hackers target universities in “payroll pirate” attacks
    Security

    Hackers target universities in “payroll pirate” attacks

    PineapplesUpdateBy PineapplesUpdateOctober 10, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Hackers target universities in “payroll pirate” attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers target universities in “payroll pirate” attacks

    A cybercrime gang tracked as Storm-2657 has been targeting university employees in the United States to hijack salary payments in “pirate payroll” attacks since March 2025.

    Microsoft Threat Intelligence analysts who looked into this campaign found that threat actors are targeting Workday accounts; However, other third-party human resources (HR) software-as-a-service (SaaS) platforms may also be at risk.

    “We observed 11 successfully hacked accounts at three universities that were used to send phishing emails to approximately 6,000 email accounts at 25 universities.” Microsoft said In a report Thursday.

    “These attacks do not represent any vulnerabilities in the Workday platform or products, but rather represent financially motivated threat actors using sophisticated social engineering tactics and taking advantage of the complete lack of multifactor authentication (MFA) or lack of phishing-resistant MFA to compromise accounts.”

    Attackers are using multiple themes custom-tailored to each target in phishing emails, ranging from warnings about disease spread on campus to reports of faculty misconduct, to trick recipients into clicking phishing links.

    Other examples include emails impersonating a university president, sharing information about compensation and benefits, or fake documents shared by HR.

    phishing email sample
    Sample Phishing Email (Microsoft)

    ​In these attacks, Storm-2657 compromised victims’ accounts via phishing emails that used adversary-in-the-middle (AITM) links to steal MFA codes, allowing threat actors to gain access to Exchange Online accounts.

    Once inside the breached accounts, they set up inbox rules to delete Workday alert notification emails, allowing them to hide other changes, including changes to payroll configuration and redirecting payments to accounts under their control after accessing victims’ Workday profiles via single sign-on (SSO).

    “Following the compromise of email accounts and payroll modifications to Workday, the threat actor took advantage of the newly accessed accounts to distribute phishing emails both within the organization and externally to other universities,” Microsoft said.

    In some cases, to establish persistence, threat actors also enrolled their own phone numbers as MFA devices for compromised accounts, through Workday Profiles or Duo MFA settings. This allowed them to avoid detection by allowing further malicious actions on their devices.

    attack flow
    Attack Flow (Microsoft)

    ​Microsoft has identified the affected customers and has reached out to some of them to assist with mitigation efforts. In today’s report, the company also shared guidance for implementing phishing-resistant MFA to help investigate and prevent these attacks and protect user accounts.

    Such “payroll pirate” attacks are a type of business email compromise (BEC) scams that target businesses and individuals who regularly make wire transfer payments.

    In 2024, the FBI’s Internet Crime Complaint Center (IC3) recorded Over 21,000 BEC fraud complaints, resulting in losses of over $2.7 billion, making it the second most lucrative crime type after investment scams.

    However, these numbers are based on known cases reported directly by victims or discovered by law enforcement, and thus likely represent only a fraction of actual losses.


    PICS BAS Summit

    attend Breach and Attack Simulation Summit and experience future of security verificationHear from top experts and see how AI-powered BAS Changing breach and attack simulations.

    Don’t miss the event that will shape the future of your security strategy

    attacks hackers payroll pirate target universities
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWhy this $7 smart plug is better than any other plug I’ve tested in my home
    Next Article India launches AI chatbot led e-commerce with ChatGPIT, Gemini, Cloud
    PineapplesUpdate
    • Website

    Related Posts

    AI/ML

    Advancing magnetic target fusion by solving an inverse problem with COMSOL Multiphysics

    October 29, 2025
    Startups

    No one pays ransomware demands anymore – so attackers have a new target

    October 28, 2025
    Startups

    Target to cut 1,800 corporate jobs – the first layoffs since 2015

    October 24, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Samsung showed me its secret HDR10+ Advanced TV samples – and I’m almost sold

    November 8, 2025

    Starbucks barista’s side hustle brings in $1 million a month

    November 8, 2025

    A new Chinese AI model claims to outperform GPT-5 and Sonnet 4.5 – and it’s free

    November 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.