Threats · 158 days ago
Storm-2755 is not just stealing Microsoft 365 passwords; it is capturing and replaying live session tokens to bypass legacy MFA protections. This allows attackers to maintain active sessions without re-authenticating, turning a phishing campaign into a stealthy business-process abuse operation. The attackers can silently redirect employee paychecks by exploiting valid sessions rather than relying solely on stolen credentials.
Microsoft researchers confirm that Storm-2755 uses SEO poisoning and malvertising to lure victims to fake Microsoft 365 login pages. These pages proxy the entire authentication flow, capturing session tokens that bypass non-phishing-resistant MFA. The attackers then use these tokens to access email accounts, search for payroll-related information, and send fraudulent direct deposit change requests to HR staff. In some cases, they directly manipulate HR software to divert salaries.
This campaign highlights that standard incident response focused on password resets and MFA enforcement may miss ongoing session hijacking risks. Attackers holding valid session tokens can continue operating as legitimate users until tokens are revoked. The threat is especially urgent for Canadian organizations with employee self-service payroll workflows, as the financial impact extends beyond email compromise to payroll fraud.
3 sources covering this story
Poisoned "Office 365" search results lead to stolen paychecks - Help Net Security
Attackers are targeting Canadian employees with a sophisticated campaign designed to covertly redirect their paychecks.
Microsoft: Canadian employees targeted in payroll pirate attacks
A financially motivated threat actor tracked as Storm-2755 is stealing Canadian employees' salary payments after hijacking their accounts in payroll pirate attacks.
Microsoft: Canadian employees targeted in payroll pirate attacks
A financially motivated threat actor tracked as Storm-2755 is stealing Canadian employees' salary payments after hijacking their accounts in payroll pirate attacks.
Microsoft Incident Response – Detection and Response Team (DART) researchers observed an emerging, financially motivated threat actor, tracked as Storm-2755, compromising Canadian employee accounts to gain unauthorized access to employee profiles and divert salary payments to attacker-controlled accounts.
Part of the PlainSec briefing for 2026-04-11