惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Blog — PlanetScale
Blog — PlanetScale
G
Google Developers Blog
Microsoft Security Blog
Microsoft Security Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
腾讯CDC
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Jina AI
Jina AI
雷峰网
雷峰网
T
Tailwind CSS Blog
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
博客园 - 司徒正美
I
InfoQ
Engineering at Meta
Engineering at Meta
Vercel News
Vercel News
小众软件
小众软件
U
Unit 42
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net

The Register - Security: Research

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits Extortion crews have their eyes on high-value AI data, Google warns Researcher shows how Claude Code can be tricked simply by asking it to summarize a website Copilot tricked into telling reseachers how to hack itself Akira ransomware scum blocked victim How the famed USENIX Security conf is managing a flood of papers in the AI era www.theregister.com Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine ChatGPT blindly trusts browser content, turning the page into a payload Russia-linked threat group put ChatGPT to work from lure to payload Kids can bypass some age checks with a drawn-on mustache What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia ORNL builds more sensitive GPS interference detector Researchers find sabotage malware that may predate Stuxnet Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus Anthropic, Google, Microsoft paid AI bug bounties – quietly Security reserchers tricked Apple Intelligence into cursing Don't open that WhatsApp message, Microsoft warns Security boffins harvest bumper crop of API keys from web Lightning-fast exploits mean patch fast, says Cisco Talos AI agents are 'gullible' and easy to turn into your minions Smooth criminals talking their way into cloud environments, Google says Snoops plant info-stealing malware on iPhones, Google warns Cybercrime up 245% since the start of the Iran war Rogue AI agents can work together to hack systems Fake applicants are sending security-killing malware AI agent hacked McKinsey chatbot for read-write access Kaspersky: No signs Coruna iPhone exploit kit made by US
Payroll pirates conned the help desk, stole employee’s pay
2026-02-11 · via The Register - Security: Research

REG AD

Cyber-crime

Payroll pirates are conning help desks to steal workers' identities and redirect paychecks

Attackers using social engineering to exploit business processes, rather than tunnelling in via tech

EXCLUSIVE When fraudsters go after people's paychecks, "every employee on earth becomes a target," according to Binary Defense security sleuth John Dwyer.

In December 2025, managed detection and response outfit Binary Defense's threat research group ARC Labs investigated a security incident in which a thief redirected a physician's salary into their own account using a very simple attack that started with a help-desk call.

"This was a combination of exploiting people and processes rather than technology," Dwyer, the deputy CTO and head of Arc Labs, told The Register in an exclusive interview. "It's technology-adjacent. This was identity theft from pure-play social engineering into exploiting a weaker-than-advised process internally to gain access."

REG AD

In a report shared exclusively with The Register, Dwyer and co-authors Danny Dubree and Eric Gonzalez detailed how the attacker used compromised credentials belonging to a shared mailbox at a healthcare facility. Binary Defenses’ incident responders can't say for certain how the attacker obtained the credentials. Dwyer said his team found no evidence of phishing and assumes the miscreant obtained the email login info from an earlier breach.

REG AD

Once the attackers gained access to the mailbox, they snooped around and determined whose identity to assume when calling the help desk to request a password and multi-factor authentication (MFA) reset.

In this case, the attacker pretended to be a physician locked out of their account and thus unable to treat patients.

"The call basically went that this person can't log into their account, they have patients they need to see right now, they need to get immediate access," Dwyer said. The fake physician's name and access-level checked out, so the help desk employee reset the password and MFA token. This gave the attacker access to the account, which enabled the rest of the payroll scam to play out.

It's technology-adjacent. This was identity theft from pure-play social engineering into exploiting a weaker-than-advised process internally to gain access

"And this is where things get very, very interesting," Dwyer said. "Over the last year where we've seen these sort of incidents, it has followed traditional business email compromise attack flows."

In one such attack targeting university employees and documented by Microsoft, the digital thieves compromised employee accounts to gain access to HR platforms like Workday and then diverted employees' direct-deposit paychecks. The attackers gained initial access through phishing emails, stole MFA codes via an adversary-in-the-middle phishing link, and then accessed the victims' Microsoft Exchange Online inboxes before hijacking their Workday profiles and sending paychecks to attacker-controlled accounts.

'Identity is the new perimeter'

"Everything happens through that access, through that mailbox in that Microsoft account," Dwyer said, adding that the attack targeting the physician looked different. After "recovering" the medico’s identity from the help desk social engineering call, the attacker authenticated from the healthcare organization's own virtual desktop infrastructure, registered new authentication devices to the account, and logged into the Workday payroll system.

Once they had logged into Workday, the crook changed the banking and direct deposit details to re-route the physician's paycheck into an attacker-controlled account.

REG AD

Using the company's own virtual infrastructure allowed the attacker to bypass security detections because the logins appeared to be a legitimate internal user with a trusted endpoint and internal IP address.

This is about process exploitation and the hijacking of identities, which makes it extraordinarily hard to identify malicious versus normal identity behavior

"With this one, the big thing that really stood out is that the attackers seem to be aware of the detection strategies against them," Dwyer said. "This attack was carried out purely outside of email and leveraging the trusted access through the VDI infrastructure. By abusing the organization's own virtual desktop infrastructure, so from a security tools point of view, everything looks normal and trusted."

The organization wasn't even aware that it had been compromised until the physician asked why they hadn’t been paid.

"It isn't always about technology hacking," Dwyer said. "This is about process exploitation and the hijacking of identities, which makes it extraordinarily hard to identify malicious versus normal identity behavior. Identity is the new perimeter, and this is a new threat vector in which your persona needs to be treated like a privileged asset, rather than just your computer or your phone."

In addition to underscoring the security threats around using shared mailboxes, this incident shows how payroll and HR platforms should be viewed as a high-value target for attackers, Dwyer added. For defenders, this requires treating payroll information as a telemetry stream for threat detection and treating payroll changes as high-risk financial events.

"The good news is we already have a model around this – lessons learned from wire fraud and pay and accounts payable fraud applies here," Dwyer said. "Changes that are made to direct deposit information should have to be confirmed in some mechanism, there should be a temporary holding period while it goes through some sort of fraud detection review, or something along those lines."

While organizations have the technology to do this, they don't necessarily have the processes in place to address this type of security and business risk, he added.

"Organizations need to consider direct deposit as a legitimate, viable threat vector," Dwyer said. "If I was a business leader, I would want to get ahead of this, because I wouldn't want to get into some sort of arbitration with an employee over a lost paycheck." ®