Stop payroll diversion scams before they start
ID: efc7563c-6609-5eb9-890b-973a2120ef8d
STIX ID: report--efc7563c-6609-5eb9-890b-973a2120ef8d
Feed Name: Pen Test Partners Blog
This blog post details a common payroll redirection fraud in which attackers harvest LinkedIn data to craft convincing emails to payroll staff requesting bank detail changes, recounting a near-miss incident and emphasizing preventative measures. It recommends organizations enforce self-service changes with MFA or verified out-of-band approvals, reject email-based change requests, use impersonation protections, and train payroll teams, while individuals should harden LinkedIn privacy (e.g., hide last names, limit job details) and reduce OSINT exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
