Payroll pirates are conning help desks to steal workers' identities and redirect paychecks
ID: a78867d8-cac5-56f1-b7c9-709711bc5bba
STIX ID: report--a78867d8-cac5-56f1-b7c9-709711bc5bba
Feed Name: The Register (Security)
Binary Defense's ARC Labs investigated a payroll diversion attack in which an attacker accessed a shared mailbox, used social engineering to get a help-desk MFA/password reset, authenticated via the organization's VDI to appear as a trusted internal user, and changed Workday direct-deposit details to steal a physician's paycheck; the report warns that identity- and process-based attacks targeting payroll are an emerging high-value threat and recommends stronger controls and fraud-detection for payroll changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
