logo

From Email to Exfiltration: How Threat Actors Steal ADP Login and Personal Data

ID: 05017d01-eb2d-5024-832c-b835597753f9

STIX ID: report--05017d01-eb2d-5024-832c-b835597753f9

Feed Name: Cofense Blog

Threat Score
65/100

Date Published: 2025-12-23

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense PDC observed a phishing campaign impersonating ADP that uses urgent violation notices and convincing fake login pages to collect user IDs, passwords, 2FA confirmation flows, and highly sensitive personal information (including SSNs); the report includes screenshots and a malicious URL (https://myadpaccess.web.app/signin/v1/pin4nas) and emphasizes user education and email security to prevent account takeover and data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.