Emerging threat: BEC payroll fraud advisory
ID: 95db3cb3-a514-527d-9315-418d25e943b7
STIX ID: report--95db3cb3-a514-527d-9315-418d25e943b7
Feed Name: Expel Blog
Date Published: 2022-07-28
Date Updated: 2026-04-27
Author: Jonathan Hencinski; Jenni Maynard; Ray Pugh; Kyle Pellett; Andrew Bentle; David Blanton; Deshawn Luu; Ben Brigida
In July 2022 Expel SOC observed widespread BEC attacks targeting O365/Okta accounts to access Workday payroll systems for direct deposit fraud; attackers commonly used legacy authentication (BAV2ROPC/IMAP/POP3) to bypass MFA, Duo push fatigue, created inbox rules to hide payroll messages, and enrolled trusted devices to maintain access. The report outlines the attack chain, detection alerts (suspicious inbox rules, legacy auth usage, abnormal Okta sessions, Duo push anomalies), and recommended steps for security teams and employees to detect and respond.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
