15.1 C
Delhi
Thursday, November 6, 2025

University Payroll Scam: Hackers Hijack Staff Salaries in Phishing Wave

US Universities Hit by Sophisticated Payroll Phishing Scam

A sophisticated phishing campaign is targeting US university staff in a coordinated payroll hijacking scheme. Since March 2025, hacking group Storm-2657 has compromised payroll accounts to redirect salary payments to accounts they control.

Key Takeaways

  • Hackers use convincing phishing emails mimicking campus alerts and HR updates
  • Attackers have targeted 25 institutions, sending 6,000 phishing emails
  • Storm-2657 primarily targets Workday but other HR platforms are vulnerable
  • Attackers use compromised accounts to spread further phishing attempts

How the University Payroll Scam Works

According to Microsoft Threat Intelligence, Storm-2657 primarily targets Workday, though other payroll and HR software could be at risk. The attackers begin with highly convincing phishing emails crafted to appeal to individual staff members.

Some messages warn of sudden campus illness outbreaks, creating urgency, while others claim faculty members are under investigation. Some emails impersonate university presidents or HR departments, sharing “important” updates about compensation and benefits.

These emails contain links that capture login credentials and multi-factor authentication codes using adversary-in-the-middle techniques. Once staff enter their information, attackers gain full account access.

Hackers lure staff with convincing emails that mimic campus alerts or HR updates and steal login details in real time. (Microsoft)

After gaining control, hackers set up inbox rules to delete Workday notifications, preventing victims from seeing alerts about changes. This allows attackers to modify payroll profiles, adjust salary settings, and redirect funds without raising immediate suspicion.

Attackers Exploit Universities at Scale

The hackers don’t stop at single accounts. Microsoft reports that from just 11 compromised accounts at three universities, Storm-2657 sent phishing emails to nearly 6,000 email addresses across 25 institutions.

By using trusted internal accounts, their emails appear more legitimate, increasing success rates. Attackers sometimes enroll their own phone numbers as MFA devices through Workday profiles or Duo MFA, giving them persistent access without needing to phish again.

Researchers have discovered that since March 2025, a hacking group known as Storm-2657 has been running “pirate payroll” attacks, using phishing tactics to gain access to payroll accounts. (Javi Sanz/Getty Images)

Microsoft emphasizes these attacks exploit human behavior rather than software flaws. The threat comes from social engineering, absence of strong phishing-resistant MFA, and insufficient protection measures.

6 Ways to Protect Against Payroll Phishing Scams

1. Limit Personal Information Online
Reduce your digital footprint to make targeted phishing attempts harder. The less information scammers can find, the less convincing their messages will be.

2. Think Before Clicking
Scammers send emails appearing from HR or university leadership about payroll or urgent issues. Never click links or download attachments unless completely certain of their legitimacy.

3. Verify Directly with Source
If an email mentions salary changes requiring action, contact HR using known contact information. Phishing emails create panic to rush decisions – verification can stop attackers.

4. Use Strong, Unique Passwords
Never reuse passwords across accounts. Scammers often use credentials stolen from other breaches. can generate and store secure passwords.

5. Enable Two-Factor Authentication
Add extra security with 2FA on all supported accounts. Even with stolen passwords, attackers cannot login without the second verification step.

6. Regularly Monitor Accounts
Check payroll and financial accounts frequently for unusual activity. Early detection prevents larger losses and alerts to potential scams.

Hackers will reroute payments after gaining access to users’ login information. (Kurt “CyberGuy” Knutsson)

Key Insight

The Storm-2657 attacks demonstrate that cybercriminals target trust rather than software. Universities are vulnerable because payroll systems handle direct payments, and staff can be manipulated through well-crafted phishing. The scale highlights how established institutions remain vulnerable to financially motivated threat actors.

Latest

Scientists Demand Ban on Chelsea Tractors After Fatal Crash Data

Imperial College researchers reveal SUVs are 82% more deadly to children and demand urgent action to remove these dangerous vehicles from British cities.

India Cuts Russian Oil Imports After US Sanctions on Rosneft, Lukoil

Major Indian refiners halt direct Russian crude purchases from December as US sanctions take effect, shifting to alternative suppliers amid market changes.

India-US Trade Agreement Talks Progress Despite Sensitive Issues

Commerce Minister Piyush Goyal confirms continuous India-US trade talks with 2025 deadline. Five rounds completed for bilateral trade agreement.

Chinese Astronauts Stranded on Space Station After Debris Damage

Three astronauts face extended space stay as their return capsule may have been damaged by orbital debris. Joint inspection underway for safe return.

Putin Orders Nuclear Test Preparation After Trump’s Move

Russia prepares for possible nuclear weapons testing as Putin responds to Trump's order. Global nuclear tensions escalate with world's largest arsenals on alert.

Topics

Scientists Demand Ban on Chelsea Tractors After Fatal Crash Data

Imperial College researchers reveal SUVs are 82% more deadly to children and demand urgent action to remove these dangerous vehicles from British cities.

India Cuts Russian Oil Imports After US Sanctions on Rosneft, Lukoil

Major Indian refiners halt direct Russian crude purchases from December as US sanctions take effect, shifting to alternative suppliers amid market changes.

India-US Trade Agreement Talks Progress Despite Sensitive Issues

Commerce Minister Piyush Goyal confirms continuous India-US trade talks with 2025 deadline. Five rounds completed for bilateral trade agreement.

Novo Nordisk Cuts Forecasts Again Amid Weight-Loss Drug Competition

Ozempic maker Novo Nordisk slashes financial guidance for the fourth time as competition from Eli Lilly and copycat drugs intensifies in the weight-loss market.

Particle Accelerator Reveals Perfect Pasta Cooking Method

Scientists used particle accelerators to discover the ideal salt level and cooking time for perfect pasta, explaining why gluten-free versions turn mushy.

BoI and SET Partner to Boost Thailand Stock Market Listings

Thailand's investment applications surge 94% as BoI and SET collaborate to promote listings in smart electronics, EVs and digital sectors.

Chinese Astronauts Stranded on Space Station After Debris Damage

Three astronauts face extended space stay as their return capsule may have been damaged by orbital debris. Joint inspection underway for safe return.

Britannia Q2 Profit Surges 23% to Rs 655 Crore, Beats Estimates

Britannia Industries reports strong Q2 results with 23% profit growth and expanded margins, while announcing new CEO appointment. Key financial highlights and outlook.
spot_img

Related Articles

Popular Categories

spot_imgspot_img