21.1 C
Delhi
Wednesday, March 4, 2026

University Payroll Scam: Hackers Hijack Staff Salaries in Phishing Wave

US Universities Hit by Sophisticated Payroll Phishing Scam

A sophisticated phishing campaign is targeting US university staff in a coordinated payroll hijacking scheme. Since March 2025, hacking group Storm-2657 has compromised payroll accounts to redirect salary payments to accounts they control.

Key Takeaways

  • Hackers use convincing phishing emails mimicking campus alerts and HR updates
  • Attackers have targeted 25 institutions, sending 6,000 phishing emails
  • Storm-2657 primarily targets Workday but other HR platforms are vulnerable
  • Attackers use compromised accounts to spread further phishing attempts

How the University Payroll Scam Works

According to Microsoft Threat Intelligence, Storm-2657 primarily targets Workday, though other payroll and HR software could be at risk. The attackers begin with highly convincing phishing emails crafted to appeal to individual staff members.

Some messages warn of sudden campus illness outbreaks, creating urgency, while others claim faculty members are under investigation. Some emails impersonate university presidents or HR departments, sharing “important” updates about compensation and benefits.

These emails contain links that capture login credentials and multi-factor authentication codes using adversary-in-the-middle techniques. Once staff enter their information, attackers gain full account access.

Hackers lure staff with convincing emails that mimic campus alerts or HR updates and steal login details in real time. (Microsoft)

After gaining control, hackers set up inbox rules to delete Workday notifications, preventing victims from seeing alerts about changes. This allows attackers to modify payroll profiles, adjust salary settings, and redirect funds without raising immediate suspicion.

Attackers Exploit Universities at Scale

The hackers don’t stop at single accounts. Microsoft reports that from just 11 compromised accounts at three universities, Storm-2657 sent phishing emails to nearly 6,000 email addresses across 25 institutions.

By using trusted internal accounts, their emails appear more legitimate, increasing success rates. Attackers sometimes enroll their own phone numbers as MFA devices through Workday profiles or Duo MFA, giving them persistent access without needing to phish again.

Researchers have discovered that since March 2025, a hacking group known as Storm-2657 has been running “pirate payroll” attacks, using phishing tactics to gain access to payroll accounts. (Javi Sanz/Getty Images)

Microsoft emphasizes these attacks exploit human behavior rather than software flaws. The threat comes from social engineering, absence of strong phishing-resistant MFA, and insufficient protection measures.

6 Ways to Protect Against Payroll Phishing Scams

1. Limit Personal Information Online
Reduce your digital footprint to make targeted phishing attempts harder. The less information scammers can find, the less convincing their messages will be.

2. Think Before Clicking
Scammers send emails appearing from HR or university leadership about payroll or urgent issues. Never click links or download attachments unless completely certain of their legitimacy.

3. Verify Directly with Source
If an email mentions salary changes requiring action, contact HR using known contact information. Phishing emails create panic to rush decisions – verification can stop attackers.

4. Use Strong, Unique Passwords
Never reuse passwords across accounts. Scammers often use credentials stolen from other breaches. can generate and store secure passwords.

5. Enable Two-Factor Authentication
Add extra security with 2FA on all supported accounts. Even with stolen passwords, attackers cannot login without the second verification step.

6. Regularly Monitor Accounts
Check payroll and financial accounts frequently for unusual activity. Early detection prevents larger losses and alerts to potential scams.

Hackers will reroute payments after gaining access to users’ login information. (Kurt “CyberGuy” Knutsson)

Key Insight

The Storm-2657 attacks demonstrate that cybercriminals target trust rather than software. Universities are vulnerable because payroll systems handle direct payments, and staff can be manipulated through well-crafted phishing. The scale highlights how established institutions remain vulnerable to financially motivated threat actors.

Latest

Kuwait shoots down US jets: All about F/A-18 Hornet that accidentally shot down F-15s amid Iran tensions

A Kuwaiti F/A-18 Hornet aircraft is suspected to have accidentally shot down three US F-15s amid ongoing tensions with Iran. 

Strikes destroy Iran building where clerics were set to choose next Supreme Leader

Iran International reported on Tuesday that Mojtaba Khamenei, the son of the late Ayatollah Ali Khamenei, was selected as his father’s successor by the countr

Thick smoke over US Consulate in Dubai after drone hits parking lot amid war

A large plume of smoke and fire was seen over the U.S. Consulate in Dubai on Tuesday, as tensions continue to escalate amid the ongoing confrontation involving

Will UAE strike Iran after wave of attacks on consulate, port and air base?

The United Arab Emirates (UAE) has dismissed a media report claiming it is weighing participation alongside the United States and Israel in military strikes on

Ayatollah Ali Khamenei to be buried in holy city of Mashhad: Iranian media

Ayatollah Ali Khamenei was originally from Mashhad, Iran’s second-largest city, where his father is buried at the Imam Reza shrine. The senior cleric, who led

Topics

D Gukesh drops to world No. 20 in live chess rankings after defeat to Aravindh Chithambaram

D Gukesh resigned in his sixth-round game against Aravindh Chithambaram, and the defeat saw his ranking fall further

Kuwait shoots down US jets: All about F/A-18 Hornet that accidentally shot down F-15s amid Iran tensions

A Kuwaiti F/A-18 Hornet aircraft is suspected to have accidentally shot down three US F-15s amid ongoing tensions with Iran. 

Arjun Tendulkar and Saaniya Chandhok look straight out of a fairytale in ivory and silver at their pre-wedding ceremony

The Tendulkars hosted a grand pre-wedding celebration in Mumbai, where Arjun Tendulkar and Saaniya Chandhok served elegance in coordinated ivory ensembles.

Career Horoscope Today, March 4, 2026: Cancer Signs Should Follow Rules and Regulations, Check the Status of Other Signs on Holi

Today's Career Horoscope 4 March 2026 (Career Horoscope): You will get an excellent platform to showcase your talent. Following rules and laws will act as a pro

Financial Horoscope Today, March 4, 2026: Scorpio Signs Can Gain Wealth on Holi, Know What Your Horoscope Says

Today's Financial Horoscope 4 March 2026 (Financial Horoscope): If you are signing a new contract, maintaining clarity in the documentation will be auspicious f

Rashmika Mandanna feeds Vijay Deverakonda with her hand; couple serve food to fans in 1st meet and greet after wedding

Rashmika Mandanna and Vijay Deverakonda met fans in Hyderabad, served them food and shared warm moments.

Strikes destroy Iran building where clerics were set to choose next Supreme Leader

Iran International reported on Tuesday that Mojtaba Khamenei, the son of the late Ayatollah Ali Khamenei, was selected as his father’s successor by the countr

Love Horoscope Today for Wednesday, March 4, 2026: Pisces will care for everyone’s happiness, find out what your sign says for Holi

Today's Love Horoscope 4 March 2026 (Love Horoscope): If there is any discord in relationships, take the initiative to talk. Seek the blessings of elders and tr
spot_img

Related Articles

Popular Categories

spot_imgspot_img