Storm-2657 Targets US Universities, Diverts Payroll via SaaS Hacks

Storm-2657 targets U.S. higher education employee accounts via phishing to redirect salary payments, exploiting weak MFA and HR SaaS platforms like Workday.

  • A threat group named Storm-2657 targets employee accounts to redirect salary payments.
  • The attacks focus on U.S. organizations, especially higher education employees using HR SaaS platforms like Workday.
  • The group uses phishing and social engineering, not software vulnerabilities, exploiting weak multi-factor authentication (MFA).
  • The attackers maintain access by adding their own phone numbers to MFA and deleting warning emails from victims’ accounts.
  • Microsoft recommends adopting phishing-resistant MFA methods and monitoring accounts for suspicious activity to prevent these attacks.

A threat actor identified as Storm-2657 has been hijacking employee accounts in U.S. organizations since early 2025 to redirect salary payments to accounts they control. The group primarily targets employees in sectors such as higher education by compromising access to third-party human resources (HR) software-as-a-service (SaaS) platforms, including Workday.

- Advertisement -

According to the Microsoft Threat Intelligence team’s report, the attacks involve phishing campaigns that harvest employee credentials and multi-factor authentication (MFA) codes. One observed approach uses an adversary-in-the-middle (AitM) phishing link to gain access to Exchange Online accounts and then exploit single sign-on (SSO) to control Workday profiles.

The attackers create rules in compromised email accounts to delete warning notifications from Workday, hiding unauthorized changes like rerouting salary payments to their accounts. They also add their own phone numbers as MFA devices to maintain persistent access. The compromised accounts then send phishing emails internally and to other universities.

Microsoft reported 11 confirmed account compromises at three universities since March 2025, leading to nearly 6,000 phishing emails sent across 25 institutions. These emails often contain urgent lures involving health issues or disciplinary notices to trick recipients into clicking malicious links.

The security firm advises organizations to implement phishing-resistant MFA methods such as FIDO2 security keys and to monitor accounts for suspicious activity, including unknown MFA devices and malicious inbox rules. The attackers do not exploit software flaws but capitalize on social engineering and insufficient MFA protections in HR SaaS platforms that manage payment details. More details are available in the Microsoft report found here.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitcoin Tops $91K as Liquidations, Venezuela News Spur Rally

Bitcoin climbed above $91,000 on Sunday as a broad token rebound extended into early...

Hut 8 expands Coinbase credit to $200M, AI deal lifts rally!

Hut 8 expanded a credit facility with Coinbase to $200 million.The company said it...

Warren Buffett Steps Down as CEO; Greg Abel Takes Helm Ahead

Warren Buffett has stepped down as CEO of Berkshire Hathaway, with his final working...

Quantum Solutions posts $4.71M unrealized ETH holdings loss.

Quantum Solutions bought about $20.6 million of Ethereum, holding roughly 5,030 ETH on its...

Phishing losses fall 83% to $83.85M as attacks shift in 2025

Annual phishing losses tied to wallet drainers fell 83% to $83.9 million in 2025.The...
- Advertisement -

Must Read

How Cryptocurrency Works For Beginners?

Welcome to the world of cryptocurrency! If you're new to this exciting and rapidly evolving landscape, you might feel like Alice in Wonderland, exploring...
Bitcoin (BTC) $ 91,389.00 1.53%
Ethereum (ETH) $ 3,147.99 1.16%
XRP (XRP) $ 2.07 1.11%
Bittensor (TAO) $ 258.42 0.56%
Polkadot (DOT) $ 2.14 0.36%
Cardano (ADA) $ 0.396503 0.39%
Chainlink (LINK) $ 13.38 1.32%
Hyperliquid (HYPE) $ 25.22 2.42%
Monero (XMR) $ 435.61 0.49%
Hedera (HBAR) $ 0.122449 0.85%
Toncoin (TON) $ 1.86 2.75%