19.1 C
Delhi
Wednesday, November 5, 2025

University Payroll Scam: Hackers Hijack Staff Salaries in Phishing Wave

US Universities Hit by Sophisticated Payroll Phishing Scam

A sophisticated phishing campaign is targeting US university staff in a coordinated payroll hijacking scheme. Since March 2025, hacking group Storm-2657 has compromised payroll accounts to redirect salary payments to accounts they control.

Key Takeaways

  • Hackers use convincing phishing emails mimicking campus alerts and HR updates
  • Attackers have targeted 25 institutions, sending 6,000 phishing emails
  • Storm-2657 primarily targets Workday but other HR platforms are vulnerable
  • Attackers use compromised accounts to spread further phishing attempts

How the University Payroll Scam Works

According to Microsoft Threat Intelligence, Storm-2657 primarily targets Workday, though other payroll and HR software could be at risk. The attackers begin with highly convincing phishing emails crafted to appeal to individual staff members.

Some messages warn of sudden campus illness outbreaks, creating urgency, while others claim faculty members are under investigation. Some emails impersonate university presidents or HR departments, sharing “important” updates about compensation and benefits.

These emails contain links that capture login credentials and multi-factor authentication codes using adversary-in-the-middle techniques. Once staff enter their information, attackers gain full account access.

Hackers lure staff with convincing emails that mimic campus alerts or HR updates and steal login details in real time. (Microsoft)

After gaining control, hackers set up inbox rules to delete Workday notifications, preventing victims from seeing alerts about changes. This allows attackers to modify payroll profiles, adjust salary settings, and redirect funds without raising immediate suspicion.

Attackers Exploit Universities at Scale

The hackers don’t stop at single accounts. Microsoft reports that from just 11 compromised accounts at three universities, Storm-2657 sent phishing emails to nearly 6,000 email addresses across 25 institutions.

By using trusted internal accounts, their emails appear more legitimate, increasing success rates. Attackers sometimes enroll their own phone numbers as MFA devices through Workday profiles or Duo MFA, giving them persistent access without needing to phish again.

Researchers have discovered that since March 2025, a hacking group known as Storm-2657 has been running “pirate payroll” attacks, using phishing tactics to gain access to payroll accounts. (Javi Sanz/Getty Images)

Microsoft emphasizes these attacks exploit human behavior rather than software flaws. The threat comes from social engineering, absence of strong phishing-resistant MFA, and insufficient protection measures.

6 Ways to Protect Against Payroll Phishing Scams

1. Limit Personal Information Online
Reduce your digital footprint to make targeted phishing attempts harder. The less information scammers can find, the less convincing their messages will be.

2. Think Before Clicking
Scammers send emails appearing from HR or university leadership about payroll or urgent issues. Never click links or download attachments unless completely certain of their legitimacy.

3. Verify Directly with Source
If an email mentions salary changes requiring action, contact HR using known contact information. Phishing emails create panic to rush decisions – verification can stop attackers.

4. Use Strong, Unique Passwords
Never reuse passwords across accounts. Scammers often use credentials stolen from other breaches. can generate and store secure passwords.

5. Enable Two-Factor Authentication
Add extra security with 2FA on all supported accounts. Even with stolen passwords, attackers cannot login without the second verification step.

6. Regularly Monitor Accounts
Check payroll and financial accounts frequently for unusual activity. Early detection prevents larger losses and alerts to potential scams.

Hackers will reroute payments after gaining access to users’ login information. (Kurt “CyberGuy” Knutsson)

Key Insight

The Storm-2657 attacks demonstrate that cybercriminals target trust rather than software. Universities are vulnerable because payroll systems handle direct payments, and staff can be manipulated through well-crafted phishing. The scale highlights how established institutions remain vulnerable to financially motivated threat actors.

Latest

UPS Cargo Plane Crashes in Louisville; Injuries Reported, Airport Closed

Massive fireball as UPS MD-11 crashes after takeoff from Louisville airport. Injuries reported, airfield closed, delivery disruptions expected.

Trump Nominates SpaceX Ally Jared Isaacman as NASA Administrator

Billionaire astronaut Jared Isaacman, known for his close ties to Elon Musk's SpaceX, nominated to lead NASA in new era of commercial space partnerships.

US Spy Jet Patrols Mexican Cartel Zone Amid Military Plans

US Navy P-8 Poseidon conducts surveillance off Mexico coast as reports emerge of planned military operations targeting drug cartels in coordinated security push.

Norway’s Wealth Fund Opposes Elon Musk’s $1 Trillion Tesla Pay Package

World's largest sovereign fund votes against record Tesla compensation deal ahead of shareholder decision that could make Musk first trillionaire.

Jaishankar to Visit Canada for G7, Marking Diplomatic Reset

India's External Affairs Minister visits Canada for G7 meeting, signaling major thaw in bilateral relations after 2023 diplomatic crisis.

Topics

IBM to Cut 2,700 Jobs in 2025 Amid AI Restructuring

IBM joins Amazon, Microsoft, Google in tech layoffs as companies shift focus to artificial intelligence. Over 30,000 jobs cut across major tech firms in 2025.

London Police: Apple Ignoring Stolen iPhone Database Amid Theft Surge

Over 80,000 iPhones stolen in London as police accuse Apple of not using national theft database to block trade-ins of stolen devices.

Bank Holiday Today: Banks Closed in 21 States for Guru Nanak Jayanti

Check if banks are open in your state on November 5. Complete state-wise list of bank closures for Guru Nanak Jayanti and upcoming holidays.

UPS Cargo Plane Crashes in Louisville; Injuries Reported, Airport Closed

Massive fireball as UPS MD-11 crashes after takeoff from Louisville airport. Injuries reported, airfield closed, delivery disruptions expected.

India Set to Become 3rd Largest Global Economy, Says FM Sitharaman

Finance Minister announces India's rapid economic ascent from 10th to soon 3rd largest economy, with 25 million lifted from poverty and banking sector revival.

SBI Q2 Net Profit Jumps 10% to Rs 20,160 Crore, Asset Quality Improves

State Bank of India reports strong Q2 results with 10% profit growth and improved asset quality. Gross NPAs decline to 1.73% as India's largest lender shows robust performance.

Trump Nominates SpaceX Ally Jared Isaacman as NASA Administrator

Billionaire astronaut Jared Isaacman, known for his close ties to Elon Musk's SpaceX, nominated to lead NASA in new era of commercial space partnerships.

Hyundai Launches Upgraded Venue SUV to Regain Market Share

Hyundai unveils new Venue compact SUV with premium features and aggressive pricing to compete with Tata, Mahindra, and Maruti in India's growing SUV market.
spot_img

Related Articles

Popular Categories

spot_imgspot_img