Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-09 and was added to the RWP archive on 2026-09-07.
Storm-2755 stole Canadian paychecks through search-bar Microsoft 365, not a university phishing wave
Microsoft DART documented Storm-2755 using SEO and malvertising for generic Office 365 terms, AiTM token theft, inbox rules, and Workday deposit changes against Canadian employees.
Bottom line up front
CONFIRMED On 9 April 2026 Microsoft DART described Storm-2755, a financially motivated payroll-pirate cluster aimed at Canadian users rather than one sector. Delivery was malvertising and SEO on generic terms such as "Office 365," not a spear-phish to a university. Fake Microsoft 365 pages (BleepingComputer cites domains such as bluegraintours[.]com) stole tokens/cookies, bypassing phishable MFA. Then: inbox rules hiding HR mail about deposits/banks, mail to HR ("question about direct deposit"), and failing that, Workday (or equivalent) session use to change bank details.
Related to Storm-2657 (US universities, already in this archive) as a method, different cluster and geography. Not merged.
Historical backfill of 9 April 2026 reporting; added 7 September 2026.
What happened
Search → fake login → token → mailbox → payroll. Microsoft disrupted some tenant infrastructure. Later 2026 Arctic Wolf-class reporting says the payroll-pirate pattern kept running; that is continuity of crime, not proof Storm-2755 equals Storm-2657.
Why it mattered
Canada-wide SEO means any employee who Googles webmail is in scope. HR dual-control on bank fields is the control that survives the kit.
Who / what was affected
Canadian employees across orgs; Workday named as an example HRIS, not a unique bug. OT not applicable.
Technical context
Same identity playbook as the university post: FIDO2, token revocation, inbox-rule detections, maker-checker on deposits. Add: block consumer search as the path to the 365 login — bookmark and Company Portal only.
Exploitation / threat status at the time
CONFIRMED Microsoft campaign mechanics and Canada targeting.
UNKNOWN loss totals.
What defenders should have done
- Canadian tenants: treat SEO 365 clones as current, not theoretical.
- Dual control on employee bank data.
- Hunt inbox rules on "direct deposit" / "bank."
RWP assessment
Confidence: High on Microsoft's distinct-cluster claim. Payroll pirate is a product line.
Defensive actions
- Passkeys for anyone who can see payroll.
- Out-of-band verify any bank-change request that arrived by email.
- Rotate sessions if a user admits they "logged into Office from Google."
Sources
- Microsoft Threat Intelligence — Investigating Storm-2755 payroll pirate attacks targeting Canadian employees
- BleepingComputer — Microsoft: Canadian employees targeted in payroll pirate attacks
- Microsoft — Storm-2657 payroll pirate attacks affecting US universities