SecurCheckCyber Centre

MICROSOFT 365 · AiTM · PAYROLL

Cyber alert: Storm-2755 and payroll fraud through Microsoft 365

Secur Cloud ·

A compromised session can become an apparently legitimate request to change bank details. This briefing helps security, IT and HR teams connect identity protection with payroll controls.

1. Storm-2755: documented facts

Microsoft’s 9 April 2026 report describes victims in Canada. Likely initial access involved poisoned search results or malicious advertising. Credentials and tokens were stolen. Attackers asked HR to change payroll details or directly manipulated a tool such as Workday. Inbox rules concealed correspondence. “Payroll pirate” describes this salary diversion; this briefing does not establish an expansion into Europe.

Read Microsoft’s original report

2. AiTM: intercept an authenticated session

In an Adversary-in-the-Middle attack, a fake portal relays authentication to the real service. It can capture the password and session cookie after second-factor approval. Replaying the cookie then reuses the session without another password entry or MFA prompt. This does not mean the original password was never exposed.

Microsoft’s explanation of AiTM

MFA remains essential

SMS codes and some push approvals do not resist AiTM phishing. Prioritise phishing-resistant methods such as FIDO2/passkeys or Windows Hello for Business, with suitable Conditional Access policies. Checking a link is an additional precaution, not the only defence.

Microsoft MFA guidance

3. Protect access and bank-detail changes

  1. Strengthen authentication

    IT should plan phishing-resistant MFA deployment, secure method registration and review policies applied to sensitive applications.

  2. Verify requests outside email

    Secur Cloud recommendation: confirm bank-detail changes through an already known channel. A request from the employee’s real account is not enough. Require a second approval before execution and record the verification.

  3. Monitor inbox rules

    Rules can move, delete or forward messages to conceal fraud. Review new rules, filters and destinations alongside unusual sign-ins. A rule alone does not prove an attack.

    Microsoft inbox-rule investigation guide

4. If a session may be compromised

Alert IT or security immediately. The response team should revoke affected access and sessions, including application-owned sessions, and verify the effect. A password change alone should not be treated as sufficient.

Revoke access: Microsoft Entra documentation

Then coordinate IT, HR and finance: preserve investigation evidence, check payroll details and follow the internal procedure for unauthorised changes. Do not wait for the next payday to review the situation.

Make verification a daily habit

Before entering credentials, open your portal from a known bookmark. To examine a doubtful link, use the checker without submitting passwords, MFA codes or session tokens.

Analyse a suspicious URL

Using your account’s free credits, within the available allowance.

Contact Secur Cloud about protecting your teams

Sources and scope

Secur Cloud awareness briefing. Adapt operational recommendations to your environment. Sources consulted on 23 September 2026: