Microsoft warns that university employees are affected by payroll attacks, so stay alert


  • Storm-2657 Hackers Attacked University Email Accounts to Phish and Redirect Salary Payments
  • Attackers exploited the lack of MFA and used AITM tactics to gain access to HR SaaS platforms.
  • Microsoft is helping victims and warning that this is a BEC-style “payroll hijack” campaign.

Hackers are breaking into human resources SaaS platform accounts at universities across the United States and redirecting salaries to their own accounts, Microsoft has warned.

Its report claims the attacks began in March 2025, when a financially motivated group tracked under the name Storm-2657 used social engineering, as well as no multi-factor authentication (MFA) in place, to break into 11 email accounts at three universities.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top