Microsoft warns that university employees are suffering from payroll attacks, so be on your guard




  • Storm-2657 hackers attack university email accounts to phishing and redirect salary payments
  • Attackers took advantage of the lack of MFA and used AITM tactics to access HR SaaS platforms.
  • Microsoft helps victims and warns that this is a BEC-style “payroll hacking” campaign

Hackers are breaking into HR SaaS platform accounts at universities across the United States and redirecting salaries to their own accounts, Microsoft warned.

Their report states that the attacks began in March 2025, when a financially motivated group tracked as Storm-2657 used social engineering, as well as the lack of multi-factor authentication (MFA), to break into 11 email accounts at three universities.



Leave a Comment

Your email address will not be published. Required fields are marked *