Categories: Cyber Security News

Attackers Redirected Employee Paychecks Without Breaching a Single System

A seemingly simple phone call became the gateway to a sophisticated attack that diverted employee paychecks without any malware or network breach.

An organization discovered this fraud when workers reported missing salary deposits. The attacker had modified direct-deposit information to funnel payments into accounts under their control.

This incident reveals a troubling trend where threat actors are abandoning complex technical methods and turning instead to social engineering

Sponsored
that targets human vulnerability.

The attack began with social engineering tactics, a method increasingly favored by threat actors. According to Palo Alto Networks’ 2025 Unit 42 Global Incident Response Report, 36 percent of incidents examined started with social engineering campaigns.

The attacker impersonated employees and contacted multiple help desk teams across payroll, IT, and HR departments.

By gathering publicly available information from social media platforms, the attacker collected enough personal details to answer verification questions.

They then convinced help desk staff to reset passwords and re-enroll multi-factor authentication devices.

The attacker even called back repeatedly to identify which verification questions were being asked, improving their chances of success on subsequent attempts.

Palo Alto Networks analysts identified the attack’s persistence mechanism as particularly concerning. The threat actor registered an external email address as an authentication method within the organization’s Azure Active Directory environment.

This step demonstrated clear intent to maintain access beyond the immediate payroll theft. The attacker systematically compromised multiple employee accounts to access sensitive payroll data.

Once authenticated, the attacker modified direct-deposit information for several workers, redirecting their salary payments to attacker-controlled bank accounts.

Sponsored

The fraudulent activity went undetected for weeks because the legitimate credentials and valid multi-factor authentication made the transactions appear normal.

The Help Desk Vulnerability: A Critical Security Gap

Help desk operations represent one of the most overlooked security weak points in modern organizations.

Password resets and MFA re-enrollment procedures, when not properly secured, become high-impact vulnerabilities.

This incident demonstrates how human-driven workflows can bypass all technical safeguards.

Attackers understand that social engineering requires no malware development, exploit discovery, or network intrusion skills.

They simply need persuasive communication and publicly available information.

The investigation eventually contained the impact to three employee accounts, but it revealed deeper systemic issues throughout the organization’s security infrastructure.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

The post Attackers Redirected Employee Paychecks Without Breaching a Single System appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Suspect arrested in connection with Abilene hit-and-run death

FORT WORTH, Texas (KTAB/KRBC) - A man wanted in connection with a deadly hit-and-run in…

9 minutes ago

Carter and Kat’s Weather Chat: AI in weather, helpful tool or future problem?

BIG COUNTRY, TEXAS (KTAB/KBRC) - In this episode of Carter and Kat’s Weather Chat, our…

9 minutes ago

Angela Ganter’s Story of Grit: Loss, Cancer, and Riding Back to the Winner’s Circle

Angela Ganter, a Texas Rodeo Hall of Fame member, shares her remarkable story of resilience,…

9 minutes ago

GlassWorm Campaign Uses 72 Malicious Open VSX Extensions to Broaden Reach

In a major escalation of supply chain attacks, the GlassWorm malware campaign has evolved to…

1 hour ago

These Genetically Engineered Brain Cells Devour Toxic Alzheimer’s Plaques

A single shot protected mice from the protein gunk implicated in Alzheimer’s disease. Alzheimer’s disease…

2 hours ago

Video Editor & Maker AndroVid

If you have an interest in video and movie making then you are going to…

2 hours ago

This website uses cookies.