What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Microsoft’s October 9, 2025 investigation describes a financially motivated campaign tracked as Storm-2657, also called “Payroll Pirates,” that stole employee identities, moved through email and single sign-on, and changed salary-payment details in HR systems. Microsoft did not report a Workday software vulnerability. The incidents involved abuse of legitimate access after accounts, MFA, or recovery paths were compromised.
The short version
The campaign targeted U.S. organizations, particularly universities. Attackers phished employees, captured passwords and sometimes MFA codes, entered compromised Exchange Online mailboxes, used SSO to reach Workday profiles, enrolled their own MFA devices, hid notification messages with inbox rules, and changed direct-deposit or other payment-election data.
Microsoft observed 11 compromised accounts at three universities since March 2025. Those accounts sent phishing messages to nearly 6,000 email accounts across 25 universities. The figure describes phishing distribution, not 6,000 confirmed payroll compromises. Microsoft’s report covers activity observed during the first half of 2025.
| Term or fact | What it means |
|---|---|
| Storm-2657 | Microsoft’s tracking name for the financially motivated activity. |
| “Payroll Pirates” | An industry label for attacks that redirect employee salary payments after identity or HR-account compromise; it is not established here as the legal name of a single criminal entity. |
| Primary documented target | U.S. higher-education organizations, although the technique can affect any employer using HR, payroll, identity, or payment SaaS. |
| Workday status | Microsoft did not attribute the incidents to a Workday product flaw or compromise of Workday’s underlying service. |
Microsoft’s investigation is at its October 9, 2025 security blog. Microsoft’s naming documentation maps Storm-2657 to Payroll Pirates at Microsoft Learn.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How the payroll-diversion attack works
-
Phishing establishes the foothold
Lures referenced illness-exposure notices, misconduct investigations, compensation updates, benefits documents, or messages impersonating institutional leaders. The objective was to make an employee sign in or disclose a code.
-
Credentials and MFA are captured
Some victims entered credentials into attacker-controlled pages. In adversary-in-the-middle (AiTM) cases, the phishing site relayed the real sign-in and captured the resulting MFA code. Microsoft also found accounts with no MFA. This does not mean every account had MFA bypassed.
-
The mailbox becomes an operations center
With Exchange Online access, attackers could read organizational communications, watch for security or HR notifications, and send convincing phishing messages from a trusted account.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
-
SSO reaches the HR platform
The stolen identity was used through single sign-on to open the employee’s Workday profile. A secure SaaS service can still be abused when a legitimate user identity or federation path is taken over.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Attackers add persistence
Microsoft observed attackers enrolling their own phone numbers as MFA devices through the victim’s HR or Duo settings. A new authenticator can let them return even after a password change if enrollment and sessions are not reviewed.
-
Notifications are concealed
Malicious inbox rules deleted, moved, or suppressed Workday messages about profile and payment changes. Some rule names consisted largely of punctuation. This is why mailbox telemetry belongs in a payroll-fraud investigation.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
-
Payment elections are altered
The attacker changed salary-payment configuration, including direct-deposit or other payment-election information, to route future funds to an account under criminal control.
-
The campaign propagates
Compromised accounts sent additional phishing messages internally and to other universities. Secondary reporting by The Hacker News, citing Silent Push, described activity across additional sectors; that broader scope should not be conflated with Microsoft’s confirmed university observations.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Was Workday hacked?
Microsoft’s report does not describe a Workday vulnerability or a breach of Workday’s underlying platform. The documented incidents abused authorized access to individual profiles after an employee identity, mailbox, MFA factor, or SSO path was compromised. The same distinction applies to other HR and payroll platforms: vendor security does not prevent an attacker who has taken over a customer account or federation layer from performing permitted actions.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Why ordinary MFA was not enough
| Authentication approach | Risk in this campaign | Better use |
|---|---|---|
| No MFA | A stolen password may be sufficient for access. | Do not permit it for payroll-connected identities. |
| SMS, one-time codes, or push approval | An AiTM page can relay the login and capture a code, or a victim can be socially engineered into approving a prompt. | Use as an interim control while stronger methods are deployed. |
| Phishing-resistant MFA | FIDO2 security keys, passkeys, and Windows Hello for Business use cryptographic origin binding designed to resist AiTM phishing. | Require it for HR, payroll, identity, finance, and help-desk administrators; provide spare authenticators and recovery procedures. |
Microsoft specifically recommends FIDO2 security keys, Windows Hello for Business, and Microsoft Authenticator passkeys in its investigation. Phishing-resistant authentication materially reduces the described attack path, but it does not eliminate risks such as device theft, malware, insider activity, or weak account recovery.
Signals defenders should investigate
Identity and MFA
- New or modified authenticators and phone numbers, especially outside a documented help-desk ticket.
- Sign-ins from unusual countries, anonymous infrastructure, residential proxies, or unfamiliar devices.
- Unusual SSO access to the HR application.
- Password resets or token revocations followed by a payment-election change.
- Successful authentication shortly after a suspected AiTM event.
Exchange Online
- New or changed inbox rules that delete, move, or hide Workday or payroll messages.
SoftDelete,HardDelete, orMoveToDeletedItemsactivity involving payroll notifications.- High-volume outbound messages from an account that normally sends little mail.
- Unexpected forwarding or mailbox-access activity.
Workday or another HR SaaS platform
Change My AccountandManage Payment Electionsevents.- New devices or MFA registrations.
- Direct-deposit, bank-account, phone, email, or other contact changes immediately before a payment change.
- Profile activity outside the employee’s normal location, hours, device, or workflow.
Event names differ by vendor. Microsoft’s listed Workday actions are not universal labels for every HR system.
A Microsoft KQL starting point
CloudAppEvents
| where Timestamp >= ago(1d)
| where Application == "Microsoft Exchange Online"
and ActionType in ("New-InboxRule", "Set-InboxRule")
| extend Parameters = RawEventData.Parameters
This query is a starting point, not a complete payroll-fraud detector. Add tenant-specific user baselines, Workday notification subjects, rule behavior, and correlation with HR audit events.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
What to do when an account or payment election looks compromised
- Reset the account password from a trusted administrative path.
- Revoke active sessions and refresh tokens; do not rely on a password change alone.
- Review, remove, and re-register MFA devices, prioritizing recently added authenticators and phone numbers.
- Revert unauthorized HR or payment changes and place a risk-based hold on pending payroll where possible.
- Notify HR, payroll, finance, identity, and incident-response teams through an independent channel, not only the affected mailbox.
- Remove malicious inbox rules and forwarding, then review mailbox activity and sent items.
- Reconfigure phishing-resistant MFA and verify that recovery methods are controlled.
- Check blast radius: identify phishing sent by the account, other SaaS access, added devices, and related identity events.
- Contact the payroll provider and receiving financial institution immediately. Payment recovery depends on detection speed, settlement status, and bank cooperation; it is not guaranteed.
- Preserve identity, mailbox, HR SaaS, and payment-audit logs before retention periods expire.
Controls that prevent a repeat
Put an independent approval around bank changes
Require two-person or out-of-band approval for direct-deposit, bank-account, payment-election, phone, email, and MFA changes—especially near a payroll cutoff. Send the alert to a verified phone, payroll queue, or manager workflow rather than solely to the potentially compromised mailbox.
Separate identity and payroll duties
The person who administers identity should not be the sole approver for payroll banking changes. Use role-based access, step-up authentication, and documented ticket correlation.
Secure the HR application as a high-value SaaS service
- Apply conditional access and strong authentication to both SSO and any direct-login path.
- Review administrator roles, API tokens, service accounts, integrations, and audit-log retention.
- Alert on payment-election changes, new MFA enrollment, and contact changes.
- Protect help-desk recovery with robust identity verification before resetting MFA or adding a phone.
Correlate systems instead of chasing isolated alerts
The highest-value detections combine events: a new MFA device plus a payment change; an unusual sign-in plus a payment-election update; or a suspicious inbox rule plus an HR login. Microsoft identifies Defender for Office 365, Defender for Cloud Apps, Defender XDR, Sentinel, and Security Copilot as possible components of such coverage. Results depend on licensing, connectors, available audit events, identity architecture, and tuned detections; no single product automatically protects every HR system.
Choosing an implementation path
| Environment | Practical priority |
|---|---|
| Small organization | Phishing-resistant MFA for payroll and HR administrators, independent bank-change approval, second-channel alerts, and a rehearsed response plan before buying a complex SIEM. |
| Microsoft-centric enterprise | Entra ID authentication-strength policies, Defender for Office 365, HR SaaS visibility through Defender for Cloud Apps, and Sentinel correlation where SOC capacity supports it. |
| Okta-centric organization | Phishing-resistant authenticators and hardened recovery in Okta Workforce Identity, plus separate email, HR-audit, and SIEM monitoring. |
| Duo deployment | Phishing-resistant methods and strict device-enrollment governance; Duo alone does not prevent an attacker who can manipulate recovery or HR workflows. |
| Large university or enterprise | Cross-system correlation among identity, email, Workday or another HR platform, payroll, finance, and help-desk records. |
Product pages for relevant capabilities include Defender for Cloud Apps, Defender for Office 365, Microsoft Sentinel, Microsoft Entra ID, Okta Workforce Identity, and Cisco Duo. FIDO2 and passkey examples are available from Yubico and Microsoft. Workday’s general security material is at Workday. These tools require appropriate configuration and do not replace payroll approvals or incident response.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchQuick Recap
What the warning proves—and what it does not
- It confirms a real, financially motivated campaign using stolen identities and legitimate HR access.
- It confirms Microsoft’s observed university-focused activity and the listed compromised-account and phishing-distribution figures.
- It does not establish that all 6,000 recipients were compromised or that every target was a payroll victim.
- It does not show that Workday was breached or that a Workday software defect caused the incidents.
- It does not limit the technique to universities, Microsoft 365, or Workday; similar identity, email, and payment workflows exist elsewhere.
- It does not guarantee that a diverted salary can be recovered. Rapid payroll and bank escalation is essential.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




