Find notable cyber news and cases, enriched with sources, timelines, and signals.

Storm-2755 payroll pirate campaign targeting Canadian employees

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The Storm-2755 campaign is stealing Canadian employees' salary payments by hijacking accounts through Microsoft 365 phishing pages, creating immediate payroll-diversion risk. The operation uses adversary-in-the-middle (AiTM) token theft to replay sessions and bypass MFA. After access is gained, the operators hide HR messages and alter direct deposit details in Workday or by email.

Related Happenings

Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA

Security Tool/Service
H score26 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...

EvilTokens Microsoft 365 consent phishing campaign

Campaign
H score39 First: 19.05.2026 14:30 Last: 19.05.2026 14:30 Sources 1

About this happening: The EvilTokens campaign rapidly compromised more than 340 Microsoft 365 organizations across five countries, showing how OAuth grant abuse can bypass MFA and c...

Code of conduct-themed Microsoft AiTM phishing campaign

Campaign
H score53 First: 05.05.2026 09:35 Last: 05.05.2026 09:35 Sources 1

About this happening: A large-scale phishing campaign used code of conduct-themed lures and legitimate email services to push victims to attacker-controlled domains and steal authentication t...

BlackFile vishing extortion campaign targeting retail and hospitality organizations

Campaign
H score37 First: 24.04.2026 21:26 Last: 24.04.2026 21:26 Sources 1

About this happening: The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...

W3LL Microsoft 365 adversary-in-the-middle phishing campaign

Campaign
H score39 First: 13.04.2026 21:55 Last: 13.04.2026 21:55 Sources 1

About this happening: The W3LL phishing operation turned into a high-volume Microsoft 365 credential-theft campaign, exposing more than 17,000 victims worldwide to BEC risk. The kit use...

Timeline

  1. 10.04.2026 14:56 2 articles · 3mo ago

    Storm-2755 payroll diversion campaign targeting Canadian employees

    Initial Disclosure

    Storm-2755 is targeting Canadian employees in payroll pirate attacks that push victims toward malicious Microsoft 365 sign-in pages, including domains such as bluegraintours[.]com, use malvertising or SEO poisoning to steal authentication tokens and session cookies, replay the stolen sessions in adversary-in-the-middle (AiTM) activity to bypass MFA, hide HR email about direct deposit or bank details, and update payroll banking information through email or direct access to Workday.

    Show sources