More

    Microsoft warns university employees are being hit by payroll attacks, so stay on your guard




    • Storm-2657 hackers hit university email accounts to launch phishing and redirect salary payments
    • Attackers exploited lack of MFA and used AITM tactics to access HR SaaS platforms
    • Microsoft is helping victims and warns this is a BEC-style “payroll pirate” campaign

    Hackers are breaking into human resources SaaS platform accounts at universities across the United States and redirecting salaries to their own accounts, Microsoft has warned.

    Its report claims the attacks started in March 2025, when a financially motivated group tracked as Storm-2657 used social engineering, as well as the fact that there was no multi-factor authentication (MFA) set up, to break into 11 email accounts at three universities.


    https://cdn.mos.cms.futurecdn.net/HLA6PU3i9RRDi5TF42BffR-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img