logo

Attackers Rerouted Employee Pay Without Breaching IT Systems

ID: afc9b7ad-68fb-59e3-af1a-1debbb22e4ff

STIX ID: report--afc9b7ad-68fb-59e3-af1a-1debbb22e4ff

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-01-19

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

An attacker used phone-based social engineering against payroll, HR and IT help desks to reset credentials and re-enroll MFA, enabling legitimate logins to payroll systems and silent redirection of three employees' direct deposits to attacker-controlled accounts; Unit 42 contained the fraud, remediated identities and hardening controls, and also discovered an unrelated persistent WannaCry infection in legacy OT systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.