🎯 Threat Intelligence

Hackers Poison Office 365 Searches to Siphon Canadian Paychecks

A single mistyped search for Office 365, and your paycheck could land in a hacker's pocket. Microsoft's Storm-2755 crew pulls off payroll heists with chilling precision.

Fake Office 365 login page from poisoned search results leading to paycheck redirection

⚡ Key Takeaways

  • Storm-2755 poisons Office 365 searches to proxy sessions and steal paychecks via HR emails. 𝕏
  • AiTM bypasses standard MFA; switch to FIDO2 passkeys for real protection. 𝕏
  • Monitor logs for Axios agents and inbox rules hiding financial keywords. 𝕏
Published by

theAIcatchup

Threat intelligence. Zero noise.

Worth sharing?

Get the best Cybersecurity stories of the week in your inbox — no noise, no spam.

Originally reported by HelpNet Security

Stay in the loop

The week's most important stories from theAIcatchup, delivered once a week.