MICROSOFT 365 · AiTM · PAYROLL
Cyber alert: Storm-2755 and payroll fraud through Microsoft 365
A compromised session can become an apparently legitimate request to change bank details. This briefing helps security, IT and HR teams connect identity protection with payroll controls.
1. Storm-2755: documented facts
Microsoft’s 9 April 2026 report describes victims in Canada. Likely initial access involved poisoned search results or malicious advertising. Credentials and tokens were stolen. Attackers asked HR to change payroll details or directly manipulated a tool such as Workday. Inbox rules concealed correspondence. “Payroll pirate” describes this salary diversion; this briefing does not establish an expansion into Europe.
Read Microsoft’s original report2. AiTM: intercept an authenticated session
In an Adversary-in-the-Middle attack, a fake portal relays authentication to the real service. It can capture the password and session cookie after second-factor approval. Replaying the cookie then reuses the session without another password entry or MFA prompt. This does not mean the original password was never exposed.
Microsoft’s explanation of AiTM
MFA remains essential
SMS codes and some push approvals do not resist AiTM phishing. Prioritise phishing-resistant methods such as FIDO2/passkeys or Windows Hello for Business, with suitable Conditional Access policies. Checking a link is an additional precaution, not the only defence.
Microsoft MFA guidance3. Protect access and bank-detail changes
Strengthen authentication
IT should plan phishing-resistant MFA deployment, secure method registration and review policies applied to sensitive applications.
Verify requests outside email
Secur Cloud recommendation: confirm bank-detail changes through an already known channel. A request from the employee’s real account is not enough. Require a second approval before execution and record the verification.
Monitor inbox rules
Rules can move, delete or forward messages to conceal fraud. Review new rules, filters and destinations alongside unusual sign-ins. A rule alone does not prove an attack.
Microsoft inbox-rule investigation guide
4. If a session may be compromised
Alert IT or security immediately. The response team should revoke affected access and sessions, including application-owned sessions, and verify the effect. A password change alone should not be treated as sufficient.
Revoke access: Microsoft Entra documentation
Then coordinate IT, HR and finance: preserve investigation evidence, check payroll details and follow the internal procedure for unauthorised changes. Do not wait for the next payday to review the situation.
Make verification a daily habit
Before entering credentials, open your portal from a known bookmark. To examine a doubtful link, use the checker without submitting passwords, MFA codes or session tokens.
Analyse a suspicious URLUsing your account’s free credits, within the available allowance.
Contact Secur Cloud about protecting your teams
Sources and scope
Secur Cloud awareness briefing. Adapt operational recommendations to your environment. Sources consulted on 23 September 2026: