Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-09 and was added to the RWP archive on 2026-09-07.
Storm-2657 stole university paychecks through mailbox rules and Workday SSO, not a payroll CVE
Microsoft documented Storm-2657 AiTM phishing against US higher-ed staff, then payroll diversion in Workday after MFA enrollment and inbox-rule concealment.
Bottom line up front
CONFIRMED On 9 October 2025 Microsoft described Storm-2657, a financially motivated actor running "payroll pirate" operations against US organizations, especially higher-education staff. Since March 2025 Microsoft had seen 11 compromised accounts at three universities used to phish nearly 6,000 mailboxes across 25 universities. The payoff was not ransomware. It was changing bank details in Workday (or any HR SaaS reached via SSO) so salary went to the actor. AiTM phishing stole session/MFA material; inbox rules hid Workday notifications; attacker-controlled phones were enrolled as MFA.
Workday was the observed platform, not a unique Workday vulnerability. Historical backfill of 9 October 2025 reporting; campaign from March 2025; added 7 September 2026.
What happened
The chain Microsoft published is identity-native:
- Tailored phishing to university staff.
- AiTM kit captures password and MFA challenge or session cookie.
- Exchange Online access. Inbox rules delete or bury payroll/Workday mail so the human does not see the "your bank account changed" notice.
- Persistence: enroll a new MFA device (Workday profile or Duo).
- SSO into Workday, swap payment destination.
IT Pro and other outlets repeated the 11 / 6,000 / 25 university figures. Those numbers are Microsoft-observed, not a national total.
A later 9 April 2026 Microsoft blog on Storm-2755 (Canadian payroll pirate) is a related pattern, different cluster. It is cited here only as evidence the method traveled; it is not merged into this US-university case.
Why it mattered
Universities combine three gifts to this actor: large staff, federated SSO into a single HR SaaS, and MFA that is still often SMS or push. Payroll diversion is quiet, legal-looking, and hits employees personally, which is how you get lawsuits without a "breach of 40 million records" headline.
SOC playbooks still hunt malware. This intrusion can be mailbox rules plus a Workday audit log.
Who / what was affected
CONFIRMED US higher-ed staff accounts; Workday as the observed HR target.
ASSESSED (high): any org where payroll is a browser app behind Entra/Okta and MFA is phishable.
UNKNOWN dollars stolen. Microsoft did not publish a loss total in the pieces we used.
OT: not applicable. Do not inflate this into critical infrastructure.
Technical context
Controls that actually break the chain:
- Phishing-resistant MFA (FIDO2, passkeys, Hello for Business). Push and SMS lose to AiTM.
- Token/session protection and Conditional Access that hates new countries and new MFA enrollments.
- Workday (or equivalent) dual control on bank-account changes; out-of-band notify to a phone number that is not the one just enrolled.
- Alert on inbox rules that target payroll, HR, or finance senders, especially immediately after a successful phish.
- Defender for Cloud Apps / equivalent SaaS audit: mailbox rule then payroll field change is the correlation Microsoft called out.
Exploitation / threat status at the time
CONFIRMED campaign through first half of 2025 into the October blog; AiTM; Workday changes.
REPORTED ongoing targeting beyond the three initially compromised schools via the 6,000-send wave.
UNKNOWN whether Storm-2657 is unique tooling or a specialist using commodity kits.
What defenders should have done
- Higher-ed CISOs: freeze MFA enrollment except from managed devices; require FIDO2 for anyone in payroll/HR/finance.
- Workday admins: maker-checker on payment destinations; alert on mass or off-cycle bank changes.
- Identity: hunt new MFA methods, inbox rules with delete/stop-processing, and Workday logins from new ASNs after a mail auth spike.
- If hit: reverse bank details, notify payroll/bank/FBI IC3, reset sessions, remove attacker MFA, and assume every mailbox the account mailed is a follow-on target.
- Do not "reset the password" and call it done while the inbox rule and enrolled phone remain.
What we know now
Storm-2755 in Canada (April 2026) shows the business model survived. The US-university write-up was a sector snapshot, not the end of payroll pirate.
RWP assessment
Confidence: High on Microsoft's campaign facts. Moderate that phishing-resistant MFA plus dual control on bank fields stops most of this class.
This is fraud as identity compromise. Budget it that way.
Defensive actions
- FIDO2 for HR/payroll privileged users this quarter, not next.
- Inbox-rule detections in production, not in a slide.
- Workday (or HRIS) change-control on employee bank data.
- Tabletop: "professor's paycheck hit the wrong routing number" with Legal and Payroll in the room.
Sources
- Microsoft Threat Intelligence — Investigating targeted payroll pirate attacks affecting US universities
- IT Pro — Payroll Pirates target US universities, Microsoft warns
- Fox News — New phishing scam targets university staff payroll
- Microsoft Threat Intelligence — Storm-2755 payroll pirate attacks targeting Canadian employees