Microsoft Sounds Alarm Over “Payroll Pirates” Hijacking HR SaaS Accounts

Microsoft has issued a warning about a threat actor identified as Storm-2657, which is hijacking employee accounts to reroute salary payments into accounts controlled by attackers. The group has reportedly focused on U.S. organizations, particularly in sectors like higher education, exploiting HR software–as–a–service (SaaS) platforms such as Workday. Although Microsoft notes that any SaaS system […]