• [email protected]
  • +995322476006
ქართული

Choose country

  • CASE GEO
  • CASE USA
  • About UsAbout Us
    • About CASEAbout CASE
    • Our teamour-team
    • CASE AnalyticsCASE Analytics
    • CASE NetworkingCASE Networking
    • Careercareer
    • Certificationcertification
    • Cyber Security in CASECyber Security in CASE
    • Success StoriesSuccess Stories
    • Contact UsGet in touch
  • Blog
  • ServicesServices
    • Personal Data ProtectionPersonal Data Protection Service and DPO Outsourcing
    • Cyber Security ServicesCyber Security Services
    • Corporate TrainingsCorporate Trainings
  • HomeLets start here
  • Mediamedia
    • Media about usMedia about us
    • News
  • CoursesCourses
  • Resources
    • Cyber PodcastCyber Podcast
    • Research and Analysis
    • E-Books
    • Security Brief
    • Frequently asked QuestionsFrequently asked Questions
logo
CASE

Email Address

[email protected]

Phone

+995322476006
  • About UsAbout Us
    • About CASEAbout CASE
    • Our teamour-team
    • CASE AnalyticsCASE Analytics
    • CASE NetworkingCASE Networking
    • Careercareer
    • Certificationcertification
    • Cyber Security in CASECyber Security in CASE
    • Success StoriesSuccess Stories
    • Contact UsGet in touch
  • Blog
  • ServicesServices
    • Personal Data ProtectionPersonal Data Protection Service and DPO Outsourcing
    • Cyber Security ServicesCyber Security Services
    • Corporate TrainingsCorporate Trainings
  • HomeLets start here
  • Mediamedia
    • Media about usMedia about us
    • News
  • CoursesCourses
  • Resources
    • Cyber PodcastCyber Podcast
    • Research and Analysis
    • E-Books
    • Security Brief
    • Frequently asked QuestionsFrequently asked Questions

Security Brief

    HomeSecurity Brief
    Microsoft Warns Of New “Payroll Pirate” Scam Stealing Employees’ Direct Deposits
Microsoft warns of new “Payroll Pirate” scam stealing employees’ direct deposits
Microsoft warns of new “Payroll Pirate” scam stealing employees’ direct deposits
by:
Mariam Abuladze
In:
Breaking News
Created:
23 Oct 2025
Share :

Microsoft has issued a warning about an ongoing phishing campaign known as “Payroll Pirate,” which targets employees’ payroll accounts and redirects their salaries to bank accounts controlled by attackers.

The scam begins with phishing emails designed to steal login credentials for Workday and other cloud-based HR systems. Once victims enter their usernames and passwords on a spoofed login page, the attackers capture these details in real time — including multi-factor authentication (MFA) codes — using an adversary-in-the-middle (AitM) setup that intercepts communication between the user and the legitimate site.

Armed with the stolen credentials, the criminals gain full access to employees’ HR profiles and alter payroll or direct-deposit settings, diverting paychecks to their own bank accounts.

Microsoft notes that this scheme highlights a growing problem with phishable MFA methods such as SMS or app-based codes. The company advises organizations to adopt FIDO2-compliant hardware security keys or passwordless authentication, which are resistant to AitM attacks and significantly reduce the risk of payroll diversion fraud.

In:
Breaking News

Search Date

Categories

  • Breaking News
  • Updates
  • Thoughts
  • footer_logo

    Advancing Security as a Profession!

    Services

    • Cyber and Information Security
    • Bank Security officer course
    • Work safety services
    • Fire safety training
    • First aid training

    Links

    • FAQ
    • Services
    • Courses
    • Privacy Policy
    • Terms

    Contact

    • +995 322 476 006
    • [email protected]
    • Georgia, Tbilisi, Pekini Ave. 30
    • Homepage
    • Main competence
    • Services
    • Courses
    • Blog
    • Contact us