logo

Poisoned “Office 365” search results lead to stolen paychecks

ID: ee361a6f-c42e-5dc8-8079-7ac8bbf44d9b

STIX ID: report--ee361a6f-c42e-5dc8-8079-7ac8bbf44d9b

Feed Name: Help Net Security

Threat Score
72/100

Date Published: 2026-04-10

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

### Executive summary Microsoft researchers uncovered Storm-2755, a financially-motivated campaign targeting Canadian employees that uses SEO poisoning, malvertising, and an AiTM proxy to capture Microsoft 365 credentials and session tokens; attackers then impersonate employees or directly access payroll SaaS to change direct-deposit details and steal paychecks. Microsoft recommends FIDO2/WebAuthn, monitoring for Axios user-agent and non-interactive periodic sign-ins, alerting on new inbox rules filtering financial keywords, and requiring out-of-band verification for payroll changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.