05/14/2026
“Payroll pirates” are getting smarter.
Microsoft recently reported on a campaign where attackers used fake Microsoft 365 login pages to steal session tokens and completely bypass MFA.
Once inside employee accounts, the attackers:
• Hid HR and payroll emails using inbox rules
• Searched for keywords like “payroll,” “finance,” and “direct deposit”
• Emailed HR teams while pretending to be employees
• In some cases, logged directly into HR platforms like Workday to reroute salary payments
What makes this attack notable isn’t just the phishing.
It’s the growing focus on attacking the human identity layer behind the business.
The attackers didn’t deploy ransomware.
They didn’t exploit servers.
They simply targeted employee identities, active sessions, and trust.
A few important reminders worth sharing with clients:
• MFA alone isn’t enough if it isn’t phishing-resistant
• Hidden inbox rules are still heavily under-monitored
• Payroll and HR workflows are becoming major attack paths
• Session hijacking is quietly becoming one of the biggest risks in cloud environments
Cybercriminals are increasingly targeting the overlap between business access and personal identity.
And payroll fraud is proving just how expensive that can become.