🚨 Storm-2657 Payroll Pirates Target Universities

Microsoft warns of attacks hijacking employee accounts to steal salaries.

πŸ’‘ HR SaaS platforms like Workday are being exploited with phishing and MFA bypass.

πŸ‘₯ Attackers use AiTM phishing links, enroll their own MFA devices, and hide email notifications to reroute payroll.

⚑ 11 accounts compromised across three universities sent phishing emails to nearly 6,000 targets.

βœ… Adopt phishing-resistant MFA like FIDO2 keys.

βœ… Review accounts for unknown MFA devices and malicious inbox rules.

βœ… Educate staff to recognize phishing tactics.

AUMINT.io helps organizations detect hidden gaps through simulations and continuous monitoring – Book your session now
.

#CyberSecurity #MFA #Phishing #PayrollSecurity #HigherEducation #MicrosoftSecurity