“Payroll Pirate” phishing scam that takes over Workday accounts steals paychecks

“Payroll Pirate” phishing scam that takes over Workday accounts steals paychecks

Microsoft has issued a warning regarding a sophisticated phishing scam known as 'Payroll Pirate,' which is designed to hijack employees' payroll accounts. This scheme diverts paycheck deposits to accounts controlled by cybercriminals after gaining access to victims’ profiles on Workday and other cloud-based HR platforms. The attackers initiate their breach by sending deceptive emails that trick employees into revealing their login credentials. Once victims enter their information, the scammers employ adversary-in-the-middle tactics to intercept multi-factor authentication (MFA) codes, allowing them to access the legitimate sites. This tactic highlights the pressing need for more secure forms of MFA, such as those compliant with FIDO standards, which are resistant to these types of attacks. After infiltrating the employees’ accounts, the criminals proceed to alter payroll settings within Workday, rerouting direct deposits from the employees' chosen accounts to their own. To further conceal their actions, the attackers set up email rules that prevent any alerts from reaching the victims when changes are made to their account information. Microsoft reported that since March 2025, they have identified 11 compromised accounts across three universities, leading to phishing attempts directed at nearly 6,000 email addresses at 25 different institutions.

Sources : Ars Technica

Published On : Oct 10, 2025, 18:10

AI
Elon Musk Launches 'Macrohard': A Groundbreaking AI Initiative from Tesla and xAI

On March 11, Elon Musk introduced an innovative joint venture between Tesla and xAI, dubbed 'Macrohard' or 'Digital Opti...

Business Today | Mar 12, 2026, 07:30
Elon Musk Launches 'Macrohard': A Groundbreaking AI Initiative from Tesla and xAI
Gaming
Google Play Unveils Exciting New Gaming Features and Expansions

In an exciting announcement at GDC 2026, Google revealed a major update to Google Play, aimed at enhancing the gaming ex...

TechCrunch | Mar 11, 2026, 23:25
Google Play Unveils Exciting New Gaming Features and Expansions
Startups
Vibe Coding's Rapid Rise Faces Key Challenges, Says Emergent CEO

Mukund Jha, CEO of Emergent, recently highlighted significant challenges confronting the burgeoning vibe coding sector. ...

Business Insider | Mar 12, 2026, 06:40
Vibe Coding's Rapid Rise Faces Key Challenges, Says Emergent CEO
AI
The Future of the Internet: Aaron Levie's Vision for AI-Driven Software

The idea of AI agents equipped with financial capabilities is gaining traction. Aaron Levie, co-founder and CEO of Box, ...

Business Insider | Mar 12, 2026, 09:10
The Future of the Internet: Aaron Levie's Vision for AI-Driven Software
Gadgets
Google Transitions to Minority Stake in New Fiber Internet Venture

In a strategic move, Google has announced that its fiber internet division, GFiber, is merging with Astound Broadband to...

CNBC | Mar 11, 2026, 23:35
Google Transitions to Minority Stake in New Fiber Internet Venture
View All News