Attack + Goal
March to November 2025 on US universities. Goal was direct financial theft via payroll redirection.
Result
Compromised accounts across 25 universities, hijacked employee salaries, and thousands of phishing emails sent.
Method
Adversary-in-the-middle phishing kit Evilginx used to harvest credentials and bypass standard multi-factor authentication.
Financial Impact
Unquantified direct losses from stolen salary deposits, alongside incident response, remediation, and audit expenses.
Between March and November 2025, a cybercrime group tracked as Storm-2657 launched a multi-month phishing campaign targeting employees across at least 25 United States universities. The threat actors used adversary-in-the-middle phishing tools to harvest corporate user logins and hijack multi-factor authentication tokens in real time. Once inside compromised Exchange Online accounts, the attackers implemented hidden inbox rules to cover their tracks and accessed internal Workday profiles through single sign-on connections. They altered direct deposit banking details to redirect employee salary payments into attacker-controlled accounts. The breached accounts were then leveraged to send thousands of personalized phishing lures to other university staff. While the financial impact of the hijacked payroll deposits remains under investigation, the campaign exposed systemic risks in higher education administrative systems lacking phishing-resistant authentication.
Detect harvested logins the moment they surface from an Evilginx-style kit, closing the opportunity window before payroll details can be redirected.