Voicemail lures slip past MFA and hunt for payroll payouts

Security company Arctic Wolf has uncovered a widespread phishing campaign aimed at Microsoft 365 accounts in organisations across Europe, Canada and the United States. Hundreds of organisations were targeted in July 2026 alone, in sectors including healthcare, education, manufacturing, government and professional services. The activity shares characteristics with a financially motivated cluster that Microsoft tracks as Storm-2755, also referred to as Payroll Pirates. The attackers hunt specifically for employees working in payroll, HR and finance.

What happens technically

The attack starts with an email that looks like a notification about a new voicemail. The subject line imitates an automated notification service and contains the organisation name and a reference code. The link leads the victim through several redirects, including infrastructure on Google Meet, Google Ads and Amazon S3, before ending on a fake sign-in page. The page sits between the victim and Microsoft, forwarding the authentication traffic to the genuine sign-in in real time. The user enters the password and completes multi-factor authentication as normal. The attacker does not need to break the MFA, because it is the finished, approved session that is captured.

With the session in hand, the attackers use Microsoft Graph to map the users in the organisation. They search for employees with roles in payroll, HR, finance and administration, and collect email about salaries, invoices, payments, banking and benefits. Arctic Wolf highlights changing the account salaries are paid to as of particular interest to the actor. In some cases the attackers also created inbox rules that automatically moved messages to deleted items and marked them as read. The access is hidden behind rotating IP addresses from private households, and automated connections refresh stolen sessions at intervals of roughly eight hours. The phishing domains were typically less than ten days old when taken into use.

Voicemail alertfake email with a linkRedirectsGoogle Meet, ads, S3Page in the middlemirrors the real sign-inSession taken overpayroll and HR searched
Figure: The link leads through several redirects to a page sitting between the user and Microsoft. MFA is completed as normal, and the attacker takes over the finished session.

What this means for you if you handle payroll and payments

The campaign shows that multi-factor authentication is no guarantee. The most important point here, as we see it, is that you can do everything right and still lose your account. You sign in on what looks like Microsoft's own page, and you approve in the app the way you always do. The protection that works against this technique is phishing-resistant authentication. The sign-in is then cryptographically bound to the genuine site, and an intermediary cannot reuse it.

The targeting of payroll and HR makes this financial crime more than an IT problem. Whoever gets into your mailbox can ask to have an account number changed. Such a request looks entirely ordinary when it comes from the right address, and the address in question is yours. Your routines around payments are therefore as important a protection as the technology. Always confirm a change of account number in a channel other than email.

Berigo recommends

  • Introduce phishing-resistant multi-factor authentication, such as passkeys, starting with the accounts that touch payroll and finance.
  • Restrict sign-ins to managed devices with conditional access, and enable continuous access evaluation in Microsoft 365.
  • Require confirmation in a separate channel before account numbers for salaries or supplier payments are changed.
  • On suspicion of compromise: revoke all active sessions, rotate passwords, re-register multi-factor authentication, and review activity in payroll and HR systems.
  • Search the logs for sign-ins that renew at fixed intervals from residential addresses, and for rules that move email to deleted items.

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch