"Payroll Pirates" are actively targeting employees in US institutions of higher education to plunder staff wages without touching the employer's systems directly.- reports Microsoft Threat Intelligence.
Threat actor Storm-2657 is using phishing emails designed to harvest multi-factor authentication (MFA) codes to gain unauthorized access to employee profiles and divert salary payments to attacker-controlled accounts. https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/ #Hackers #CyberAttack #MFA #Phishing #CyberSecurity #Microsoft #Storm2657 #PayrollPirate #Security
