#Microsoft warns of new “Payroll Pirate” #scam stealing employees’ direct deposits

Microsoft is warning of an active scam that diverts employees' #paycheck payments to attacker-controlled accounts after first taking over their profiles on #Workday or other cloud-based #HR services

#PayrollPirate , gains access to victims’ HR portals by sending them #phishing emails that trick the recipients into providing their #credentials for logging in to the cloud account
#security

https://arstechnica.com/security/2025/10/payroll-pirate-phishing-scam-that-takes-over-workday-accounts-steals-paychecks/

Microsoft warns of new “Payroll Pirate” scam stealing employees’ direct deposits

Among other things, the scammers bypass multi-factor authentication.

Ars Technica