Microsoft Warns University -employees are being hit by payroll attacks so stay on your guard


  • Storm-2657 hackers hit the university’s e-mail accounts to launch phishing and redirect wage payments
  • Attackers utilized a lack of MFA and used AITM tactics to access HR SAAS platforms
  • Microsoft helps victims and warns that this is a BEC style “payroll” campaign

Hackers break into Human Resources SaaS platform accounts at universities across the United States and redirects wages to their own accounts, Microsoft has warned.

Its report claims that the attacks started in March 2025, when an economically motivated group is traced as Storm-2657 used social engineering, as well as the fact that there was no multi-factor approval (MFA) created to break into 11 e-mail accounts at three universities.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top