December 10, 2025

Web and Technology News

Microsoft warns of new “Payroll Pirate” scam stealing employees’ direct deposits

Microsoft is warning of an active scam that diverts employees' paycheck payments to attacker-controlled accounts after first taking over their profiles on Workday or other cloud-based HR services.

Payroll Pirate, as Microsoft says the campaign has been dubbed, gains access to victims’ HR portals by sending them phishing emails that trick the recipients into providing their credentials for logging in to the cloud account. The scammers are able to recover multi-factor authentication codes by using adversary-in-the-middle tactics, which work by sitting between the victims and the site they think they’re logging in to, which is, in fact, a fake site operated by the attackers.

Not all MFA is created equal

The attackers then enter the intercepted credentials, including the MFA code, into the real site. This tactic, which has grown increasingly common in recent years, underscores the importance of adopting FIDO-compliant forms of MFA, which are immune to such attacks.

Read full article

Comments

Previous Article

The underdog AI startups on a16z’s top 50 list

Next Article

Google Chrome silences those pesky notifications

You might be interested in …

Applications security startup Apiiro pulls in $100M Series B from A-list investors

At a time when large rounds are a thing of the past, especially in the early stages, Apiiro, an applications security startup, announced a $100 million Series B today from several top shelf Silicon Valley firms. What is attracting this kind of investment in a time when investors otherwise are in a period of belt […]

Applications security startup Apiiro pulls in $100M Series B from A-list investors by Ron Miller originally published on TechCrunch

Leave a Reply

Your email address will not be published. Required fields are marked *