Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering
ID: 25d21da2-6231-58b9-8d0f-afa90637e4a8
STIX ID: report--25d21da2-6231-58b9-8d0f-afa90637e4a8
Feed Name: Palo Alto Networks Unit 42
Unit 42 investigated a payroll diversion caused by social engineering: attackers impersonated employees, manipulated payroll/HR/IT help desks to reset passwords and re-enroll MFA, then changed direct-deposit details to steal paychecks (impact limited to three accounts). The response contained the compromise, reversed fraudulent changes, and produced recommendations to strengthen help-desk verification, MFA enforcement, logging, and identity governance; the engagement also uncovered a separate, persistent WannaCry presence in the client’s OT environment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
