Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Microsoft Tools to Target HR and Payroll

Hackers Exploit Microsoft Tools to Target HR and Payroll

Posted on June 15, 2026 By CWS

Cyber attackers are utilizing Microsoft’s cloud technologies to surreptitiously locate and exploit payroll and HR personnel within corporate systems, diverting salaries to accounts they control. Organizations are urgently responding as this threat spreads across sectors and regions.

Innovative Attack Techniques

The attackers employ a sophisticated method that avoids traditional malware deployment. Instead, they use adversary-in-the-middle (AiTM) phishing tactics to intercept active login sessions, masquerading as a Microsoft 365 login page. This approach allows them to bypass multi-factor authentication, accessing accounts without the need for passwords.

Reports from Security Risk Advisors and BushidoToken Threat Intel highlight the challenge of distinguishing legitimate activity from malicious actions due to the use of Microsoft’s tools. This strategy leaves endpoint detection systems with little to alert on.

Exploiting Microsoft Graph API

Once inside a Microsoft 365 account, attackers leverage the Microsoft Graph API, a developer tool for querying directory data. They conduct bulk searches for employees related to payroll, HR, and finance, rapidly compiling a list of targets.

The campaign, linked to Microsoft-tracked entities Storm-2755 and Storm-2657, has been detected in various industries, including healthcare and manufacturing. The ultimate aim is to alter payroll settings to redirect salaries to attacker-controlled accounts.

Defensive Measures and Recommendations

Detection relies heavily on Microsoft Entra sign-in telemetry and Graph activity logs. Enabling detailed logging and sending this data to security monitoring systems is crucial.

Implementing phishing-resistant multi-factor authentication, such as FIDO2 keys or certificate-based methods, is advised. Standard authentication techniques like SMS codes are inadequate against AiTM tactics.

Compromised organizations must revoke sessions, reset credentials, and audit application permissions thoroughly. Payroll changes during the breach should be scrutinized and verified independently.

For further updates, follow us on Google News, LinkedIn, and X to receive the latest in cybersecurity developments.

Cyber Security News Tags:AiTM phishing, Authentication, cyber threat, Cybersecurity, data protection, HR security, IT security, Microsoft 365 security, Microsoft Graph, multi-factor authentication, network intrusion, payroll fraud, phishing attacks, security risk, threat intelligence

Post navigation

Previous Post: NewCore Launches with $66 Million in Seed Funding
Next Post: Chinese Cyber Group Targets North American Research

Related Posts

CISA Warns of Federal Agencies Not Fully Patching Actively Exploited Cisco ASA or Firepower Devices CISA Warns of Federal Agencies Not Fully Patching Actively Exploited Cisco ASA or Firepower Devices Cyber Security News
Kali Linux 2025.4 Released With 3 New Hacking Tools and Wifipumpkin3 Kali Linux 2025.4 Released With 3 New Hacking Tools and Wifipumpkin3 Cyber Security News
Critical Convoy Vulnerability Let Attackers Execute Remote Code on Affected Servers Critical Convoy Vulnerability Let Attackers Execute Remote Code on Affected Servers Cyber Security News
13-year-old Critical Redis RCE Vulnerability Let Attackers Gain Full Access to Host System 13-year-old Critical Redis RCE Vulnerability Let Attackers Gain Full Access to Host System Cyber Security News
North Korean Hackers Attacking Unmanned Aerial Vehicle Industry to Steal Confidential Data North Korean Hackers Attacking Unmanned Aerial Vehicle Industry to Steal Confidential Data Cyber Security News
F5 Breached – Hackers Stole BIG-IP Source Code and Undisclosed Vulnerabilities Data F5 Breached – Hackers Stole BIG-IP Source Code and Undisclosed Vulnerabilities Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hack Targets French Government Messaging Platform
  • Microsoft 365 Flaw Risked Email and File Theft
  • Ad Blocker Extensions Secretly Capture AI Chats
  • Cyberattack Disrupts Operations of Major Australian Sugar Producer
  • Weekly Cybersecurity Highlights: Chrome 0-Day & More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hack Targets French Government Messaging Platform
  • Microsoft 365 Flaw Risked Email and File Theft
  • Ad Blocker Extensions Secretly Capture AI Chats
  • Cyberattack Disrupts Operations of Major Australian Sugar Producer
  • Weekly Cybersecurity Highlights: Chrome 0-Day & More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark