Attackers Rerouted Employee Pay Without Breaching IT Systems
ID: afc9b7ad-68fb-59e3-af1a-1debbb22e4ff
STIX ID: report--afc9b7ad-68fb-59e3-af1a-1debbb22e4ff
Feed Name: GBHackers
Threat Score
An attacker used phone-based social engineering against payroll, HR and IT help desks to reset credentials and re-enroll MFA, enabling legitimate logins to payroll systems and silent redirection of three employees' direct deposits to attacker-controlled accounts; Unit 42 contained the fraud, remediated identities and hardening controls, and also discovered an unrelated persistent WannaCry infection in legacy OT systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
