HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Storm‑2755 Payroll Pirate Hijacks Canadian Employee Accounts to Divert Salaries

Microsoft’s DART team uncovered Storm‑2755, a threat actor stealing Canadian employee credentials to access payroll systems and reroute salary payments. The incident highlights the financial and data‑privacy risks of compromised payroll services for third‑party risk managers.

LiveThreat™ Intelligence · 📅 April 09, 2026· 📰 microsoft.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
microsoft.com

Payroll “Pirate” Threat Actor Storm‑2755 Hijacks Canadian Employee Accounts to Divert Salaries

What Happened — Microsoft’s DART team identified a financially‑motivated threat group, Storm‑2755, that compromises Canadian employee credentials, accesses internal payroll systems, and redirects salary payments to attacker‑controlled accounts. The campaign leverages credential‑theft techniques to harvest employee profiles and manipulate payroll data.

Why It Matters for TPRM

  • Direct financial loss to client organizations and their employees.
  • Exposure of personally identifiable information (PII) and payroll data.
  • Demonstrates a supply‑chain risk where a vendor’s payroll service becomes a conduit for fraud.

Who Is Affected — Canadian enterprises across all sectors that use third‑party payroll processing services (e.g., ADP, Paychex, Ceridian) and their employees.

Recommended Actions

  • Verify that payroll vendors enforce multi‑factor authentication (MFA) for employee accounts.
  • Conduct credential‑security assessments for any third‑party payroll or HR platforms.
  • Implement transaction‑level controls and alerts for anomalous salary disbursements.

Technical Notes — Attack vector appears to be phishing‑based credential compromise, leading to unauthorized access of payroll applications. No specific CVE is cited. Data types accessed include employee personal data, banking details, and salary information. Source: Microsoft Security Blog

📰 Original Source
https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.