Attackers Hijack Paychecks via Help-Desk Calls
Attackers hijack paychecks without breaching a single system, exploiting human behavior instead of deploying malware or hacking tools. The scheme came to light when employees reported missing salary deposits. Investigators soon uncovered that the attacker had modified direct-deposit details and rerouted funds to bank accounts under their control.
The attacker used social engineering to impersonate employees and repeatedly contacted help desks in HR, IT, and payroll teams. By harvesting data from social media, the attacker answered verification questions and convinced staff to reset passwords and re-enroll devices for multi-factor authentication.
Palo Alto Networks’ Unit 42 found the intruder exploited Azure’s authentication settings to maintain long-term access. Weeks passed before detection, due to legitimate credentials masking suspicious activity.
The breach affected three employee accounts and exposed a critical weakness in help desk security procedures. It underscores how easily attackers hijack paychecks using trusted communication channels.
Read the full story at https://cybersecuritynews.com/attackers-redirected-employee-paychecks/
