🚨 Storm-2657 Payroll Pirates Target Universities

Microsoft warns of attacks hijacking employee accounts to steal salaries.

💡 HR SaaS platforms like Workday are being exploited with phishing and MFA bypass.

👥 Attackers use AiTM phishing links, enroll their own MFA devices, and hide email notifications to reroute payroll.

⚡ 11 accounts compromised across three universities sent phishing emails to nearly 6,000 targets.

✅ Adopt phishing-resistant MFA like FIDO2 keys.

✅ Review accounts for unknown MFA devices and malicious inbox rules.

✅ Educate staff to recognize phishing tactics.

AUMINT.io helps organizations detect hidden gaps through simulations and continuous monitoring – Book your session now
.

#CyberSecurity #MFA #Phishing #PayrollSecurity #HigherEducation #MicrosoftSecurity