Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-09 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity

Storm-2755 stole Canadian paychecks through search-bar Microsoft 365, not a university phishing wave

Microsoft DART documented Storm-2755 using SEO and malvertising for generic Office 365 terms, AiTM token theft, inbox rules, and Workday deposit changes against Canadian employees.

RWP Ventures · 2026-09-07 · event 2026-04-09 · 2 min read · priority 8.0

Bottom line up front

CONFIRMED On 9 April 2026 Microsoft DART described Storm-2755, a financially motivated payroll-pirate cluster aimed at Canadian users rather than one sector. Delivery was malvertising and SEO on generic terms such as "Office 365," not a spear-phish to a university. Fake Microsoft 365 pages (BleepingComputer cites domains such as bluegraintours[.]com) stole tokens/cookies, bypassing phishable MFA. Then: inbox rules hiding HR mail about deposits/banks, mail to HR ("question about direct deposit"), and failing that, Workday (or equivalent) session use to change bank details.

Related to Storm-2657 (US universities, already in this archive) as a method, different cluster and geography. Not merged.

Historical backfill of 9 April 2026 reporting; added 7 September 2026.

What happened

Search → fake login → token → mailbox → payroll. Microsoft disrupted some tenant infrastructure. Later 2026 Arctic Wolf-class reporting says the payroll-pirate pattern kept running; that is continuity of crime, not proof Storm-2755 equals Storm-2657.

Why it mattered

Canada-wide SEO means any employee who Googles webmail is in scope. HR dual-control on bank fields is the control that survives the kit.

Who / what was affected

Canadian employees across orgs; Workday named as an example HRIS, not a unique bug. OT not applicable.

Technical context

Same identity playbook as the university post: FIDO2, token revocation, inbox-rule detections, maker-checker on deposits. Add: block consumer search as the path to the 365 login — bookmark and Company Portal only.

Exploitation / threat status at the time

CONFIRMED Microsoft campaign mechanics and Canada targeting.

UNKNOWN loss totals.

What defenders should have done

  1. Canadian tenants: treat SEO 365 clones as current, not theoretical.
  2. Dual control on employee bank data.
  3. Hunt inbox rules on "direct deposit" / "bank."

RWP assessment

Confidence: High on Microsoft's distinct-cluster claim. Payroll pirate is a product line.

Defensive actions

  1. Passkeys for anyone who can see payroll.
  2. Out-of-band verify any bank-change request that arrived by email.
  3. Rotate sessions if a user admits they "logged into Office from Google."

Sources

  1. Microsoft Threat Intelligence — Investigating Storm-2755 payroll pirate attacks targeting Canadian employees
  2. BleepingComputer — Microsoft: Canadian employees targeted in payroll pirate attacks
  3. Microsoft — Storm-2657 payroll pirate attacks affecting US universities