A widespread phishing campaign is breaking into Microsoft 365 accounts at organizations in the United States, Canada, and Europe and then quietly collecting email tied to payroll and finance work. Arctic Wolf says the activity overlaps with Microsoft's Storm-2755 'Payroll Pirates' cluster and uses adversary-in-the-middle (AiTM) phishing pages to proxy real Microsoft logins, bypass multi-factor authentication, maintain sessions roughly every eight hours, and hide follow-on access behind residential proxy traffic. Targeted sectors include healthcare, education, manufacturing, government, and professional services.
Why it matters: This is an active account-takeover campaign aimed at the people who handle money, making payroll fraud and business email compromise more likely even when MFA is enabled. Organizations using Microsoft 365 should urgently harden phishing defenses, review suspicious sign-ins and session persistence, and warn staff about voicemail-themed login lures.
info@thehackernews.com (The Hacker News)
2026.08.07
96% relevant
This appears to describe the same underlying event: an adversary-in-the-middle phishing campaign hijacking Microsoft 365 accounts in order to collect payroll and finance-related emails. The article is an additional report on that same campaign and target set rather than a distinct incident.
Arctic Wolf Labs
2026.08.06
100% relevant
This article establishes a concrete, ongoing phishing campaign with named overlap to Storm-2755, cross-sector targeting, and actionable technical details about the Microsoft 365 intrusion method and post-compromise behavior.
← Back to all stories