Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceeducation-sector-threatcredential-access-methodbusiness-email-compromise

Payroll Pirate Phishing Attacks Targeting US University Employees

Updated 2mo agoFirst seen Oct 9, 202512 sources

Cybercriminals identified as 'payroll pirates' have launched a targeted phishing campaign against US universities, aiming to divert salary payments from employees to accounts under their control. Microsoft Threat Intelligence reported that since March 2025, at least 11 accounts across three universities were successfully compromised, with phishing emails sent to nearly 6,000 recipients at 25 different universities. The attackers primarily targeted third-party platforms such as Workday, which are commonly used for HR and payroll management in higher education institutions. The phishing emails often contained malicious links and were crafted to steal multifactor authentication (MFA) codes, enabling the attackers to bypass security measures and hijack employee accounts. Once inside a compromised account, the threat actors established inbox rules to automatically delete warning emails from Workday, thereby concealing unauthorized changes to bank account information. This allowed the attackers to redirect salary payments without immediate detection by the victims. The phishing lures were varied, with some emails referencing COVID-19 exposure or faculty misconduct, and often included links to Google Docs to increase credibility. In one instance, a phishing email about illness exposure was sent to 500 individuals at a single organization. Microsoft attributed the campaign to a group it tracks as Storm-2657 and has proactively contacted affected customers with mitigation advice. The campaign demonstrates a sophisticated understanding of university HR processes and leverages social engineering themes relevant to academic environments. The attackers' use of MFA code theft highlights the evolving tactics used to bypass common security controls. Microsoft emphasized that while Workday was a primary target, other HR and payment systems could also be at risk. The scale of the campaign, with thousands of potential victims, underscores the need for heightened vigilance and improved security awareness among university staff. The incident has raised concerns about the security of third-party platforms used for payroll and HR functions in the education sector. Workday, the platform most frequently targeted, did not respond to requests for comment regarding the incident. Microsoft’s response included sharing technical indicators and recommended best practices to help organizations defend against similar attacks. The campaign is ongoing, and universities are urged to review their security protocols, especially around MFA and email filtering. The incident highlights the persistent threat of phishing and the importance of layered security defenses in protecting sensitive financial information.

Share:
Payroll Pirate Phishing Attacks Targeting US University Employees
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Apr 10, 20262mo ago

Microsoft reports Storm-2755 payroll attacks targeting Canadian employees

Microsoft said financially motivated threat actor Storm-2755 is targeting Canadian employees by hijacking Microsoft 365 accounts and redirecting salary payments. The campaign uses adversary-in-the-middle phishing to steal session cookies and OAuth tokens, then abuses HR workflows and platforms such as Workday to alter direct-deposit details.

Microsoft: Canadian employees targeted in payroll pirate attacks
Oct 10, 20259mo ago

Workday urges customers to enable phishing-resistant MFA

Following reporting on the campaign, Workday advised customers to use phishing-resistant MFA and additional data-protection measures to reduce the risk of payroll-account takeover.

Oct 9, 20259mo ago

Microsoft publicly discloses Storm-2657 'payroll pirate' campaign

On October 9, 2025, Microsoft Threat Intelligence published details of the 'payroll pirate' campaign, attributing it to Storm-2657 and stating the activity abused weak identity protections rather than exploiting a Workday vulnerability.

Microsoft notifies some affected customers and prepares mitigation guidance

As part of its investigation, Microsoft said it contacted some affected customers and developed hunting, remediation, and incident-response guidance focused on removing malicious inbox rules, rogue MFA devices, and reversing payroll changes.

Jun 30, 20251y ago

Compromised university accounts are used to expand phishing campaign

During the first half of 2025, the attackers used compromised university email accounts to send additional phishing messages, ultimately targeting nearly 6,000 accounts across 25 universities. The lures included institution-tailored themes such as HR notices, misconduct allegations, and health-related alerts.

Mar 1, 20251y ago

Attackers successfully compromise accounts at three universities

Microsoft observed 11 successful account compromises across three universities. The attackers used access to Exchange Online and SSO-linked HR platforms such as Workday to alter employee payroll direct-deposit details and divert salary payments.

Storm-2657 begins payroll-diversion attacks on U.S. universities

Beginning in March 2025, Microsoft observed the financially motivated actor Storm-2657 targeting U.S.-based organizations, especially universities, with phishing aimed at stealing credentials and MFA codes to hijack payroll accounts.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
Threat actors
2 linked
Affected products
8 linked
WorkdayExchange OnlineGoogle DocsGoogle DocsDuoGoogle DocsMicrosoft Entra IdWindows Hello
Organizations
15 linked
Microsoft CorporationWorkdayKnowbe4GoogleStorm-2657Duo SecurityCisco SystemsMalwarebytesLinkedinHunt.ioPicus SecurityRecorded Futurefbi_ic3XSilent Push
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.