logo

Payroll Pirates in the North: Microsoft Unmasks ‘Storm-2755’ and the Theft of Canadian Salaries

ID: 9ba01d91-8b85-5645-abba-470201f85957

STIX ID: report--9ba01d91-8b85-5645-abba-470201f85957

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft DART has identified Storm-2755, a financially motivated actor using malvertising and SEO poisoning to lure Canadian users into Adversary-in-the-Middle traps that hijack authenticated sessions and bypass MFA. The group conducts “payroll pirate” operations to change direct deposit details—via social-engineered HR emails or by manually manipulating HR SaaS (e.g., Workday)—and Microsoft has undertaken disruption efforts; recommended mitigations include employee education, hardened HR SaaS access controls, and out-of-band verification for payroll changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.