logo

Attackers Redirected Employee Paychecks Without Breaching a Single System

ID: c533da7d-c8fc-5bbf-bcc0-c97c6349d387

STIX ID: report--c533da7d-c8fc-5bbf-bcc0-c97c6349d387

Feed Name: cybersecurityNews.com

Threat Score
58/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A financially motivated attack used persistent social engineering against help-desk, payroll, IT, and HR teams to reset credentials, re-enroll MFA, and register an external authentication email in Azure AD, allowing the attacker to modify employees' direct-deposit details and divert paychecks to attacker-controlled accounts; the scheme involved no malware or network breach and was detected after several employees reported missing salary deposits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.