In recent years, cyber attacks have evolved well beyond traditional viruses and malware. One of the most sophisticated and concerning techniques is social engineering, which exploits human psychology rather than technical vulnerabilities. An emblematic case is the recent campaign of attacks targeting payroll management systems.
A group of cybercriminals orchestrated a series of sophisticated attacks targeting corporate payroll systems through a help desk manipulation technique. The attackers impersonated legitimate employees, contacting technical support services by phone to request password resets. Once they bypassed identity verification protocols, they managed to reset multi-factor authentication (MFA) devices and gain access to payroll systems. The next step was to modify bank transfer details, redirecting salaries to accounts controlled by the attackers.
To ensure persistent access, the malicious actors registered external email addresses as authentication methods in Azure AD, making their detection more difficult. The attack was only discovered when some employees reported not receiving their salaries. Subsequent investigations revealed suspicious account changes dating back several weeks. Fortunately, no evidence was found of wider lateral movement within corporate networks or exfiltration of sensitive data.
This type of attack is particularly concerning because it demonstrates how even organizations with solid technological security systems can be vulnerable through the human factor. The immediate impact was financial, with the loss of numerous employees’ salaries, but long-term consequences include compromised corporate credentials and potential reputational damage for the affected organizations.
To protect against similar threats, companies should strengthen identity verification protocols for password reset requests, implement systems to detect anomalous activity on employee accounts, and conduct regular cybersecurity training for help desk staff. Users, for their part, should regularly monitor their paychecks and immediately report any anomalies.
- In conclusion:
- Social engineering attacks represent a growing threat even for technically well-protected organizations
- Staff training, particularly for help desk operators, is essential to prevent this type of compromise
- Continuous monitoring of account activities and financial flows can help to promptly identify similar attacks
- Sources:
- https://unit42.paloaltonetworks.com/social-engineering-payroll-pirates/
- https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/
- https://www.okta.com/newsroom/articles/payroll-pirates-target-help-desks-to-siphon-employee-paychecks/
Source: Unit 42