logo

Microsoft: Hackers target universities in “payroll pirate” attacks

ID: e23529cd-cecd-5089-9db4-45a6a2a09d62

STIX ID: report--e23529cd-cecd-5089-9db4-45a6a2a09d62

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-10-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft observed a coordinated 'payroll pirate' campaign by Storm-2657 that used tailored phishing (including AITM links) to bypass MFA, compromise Exchange Online accounts at several U.S. universities, set mailbox rules to hide notifications, access Workday via SSO, and alter payroll to redirect salary payments; 11 accounts at three universities were confirmed compromised and phishing messages were sent to nearly 6,000 addresses across 25 universities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.