The Containment Era is here. →Explore

Executive Summary

In March 2025, a financially motivated threat group tracked as Storm-2657 launched a series of "payroll pirate" attacks targeting U.S. university staff. The attackers leveraged advanced social engineering and adversary-in-the-middle (AITM) phishing techniques to compromise HR-related SaaS accounts, notably Workday. After stealing MFA credentials, they accessed Exchange Online accounts, manipulated payroll settings to hijack salary payments, set inbox rules for concealment, and enrolled attacker-controlled MFA devices for persistence. At least 11 accounts across three universities were breached, enabling phishing campaigns to almost 6,000 recipients spanning 25 institutions.

The incident showcases a significant escalation in business email compromise (BEC) targeting the education sector, exploiting gaps in MFA and SSO implementations. With BEC attacks surging industry-wide—resulting in multimillion-dollar annual losses—this campaign emphasizes the urgent need for phishing-resistant MFA and robust email monitoring across academia and beyond.

Why This Matters Now

This breach demonstrates that even sophisticated SaaS and cloud environments are vulnerable when phishing-resistant MFA is not enforced. The surge in BEC attacks targeting universities highlights an industry-wide gap, making the deployment of resilient identity and access controls, as well as improved user awareness, urgently necessary.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Key gaps included lack of phishing-resistant MFA, insufficient monitoring of inbox rules, and inadequate internal email segmentation, all critical for HIPAA, PCI DSS, and NIST frameworks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, strong policy enforcement for egress and internal traffic, and comprehensive anomaly detection could have significantly limited the blast radius, detected abuse, or blocked malicious actions across every stage of this attack. Fine-grained access control and visibility would have disrupted attacker persistence and potential lateral SaaS movement.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Rapid detection of credential harvesting and anomalous authentication attempts.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Visibility into privilege changes and real-time policy audits.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Lateral movement blocked between user identities and sensitive SaaS systems.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outbound connections to malicious C2 domains detected and/or blocked.

Exfiltration

Control: Threat Detection & Anomaly Response

Mitigation: Real-time alerts on anomalous payroll changes and data exfiltration attempts.

Impact (Mitigations)

Comprehensive incident visibility supports rapid containment and recovery.

Impact at a Glance

Affected Business Functions

  • Payroll Processing
  • Human Resources Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Unauthorized access to employee payroll information, including bank account details, leading to potential identity theft and financial fraud.

Recommended Actions

  • Enforce Zero Trust segmentation and least-privilege access policies to prevent lateral movement between user identities and critical SaaS systems.
  • Mandate phishing-resistant MFA and continuously monitor for anomalous authentication activity across cloud and SaaS environments.
  • Deploy centralized, real-time anomaly detection to baseline user and admin behavior and accelerate incident response.
  • Implement granular egress policy enforcement to block unauthorized outbound connections and exfiltration attempts.
  • Establish robust visibility and control across multi-cloud workloads and SaaS to quickly detect, audit, and remediate identity or privilege abuse.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image