Microsoft Warns of Payroll Pirate Scam Hijacking Employee Paychecks
arstechnica.com
|
Contributed by: Drex DeFord
Summary
Microsoft has alerted healthcare organizations to the "Payroll Pirate" scam, which exploits vulnerabilities in cloud-based HR services to redirect employee paychecks to attacker-controlled accounts. By utilizing phishing tactics to capture login credentials and intercept multi-factor authentication (MFA) codes, scammers can gain unauthorized access to HR portals like Workday. This incident underscores the inadequacies of certain MFA methods, prompting a critical need for stronger security measures, such as FIDO-compliant solutions, to protect sensitive employee data. Healthcare professionals must reassess their cybersecurity protocols to guard against increasingly sophisticated attacks that compromise financial and personal information.