University Payroll Phishing: Storm-2657 Tactics Keep Spreading
What happened
A financially motivated hacking group that Microsoft tracks as Storm-2657 has been running what researchers call "pirate payroll" attacks against American universities since March 2025. The group sent phishing emails to roughly 6,000 addresses across 25 institutions 3. The goal is direct theft, not espionage or ransom. Attackers try to get into employees' Workday HR accounts, then reroute salary deposits to accounts they control 3.
The lures relied on campus anxieties. According to the reporting on Microsoft's findings, the emails referenced illness outbreaks on campus and internal investigations, the kinds of messages a staff member might feel obliged to open quickly 3. Once credentials were captured, the payroll system itself became the payout mechanism.
The pattern hasn't faded
What stands out in the months since is how closely university security advisories track the same themes. None of the following campus warnings attributes its incidents to Storm-2657, and it would be a mistake to assume they all trace to one actor. But together they suggest the payroll-and-HR playbook has become a standard approach in higher-education phishing.
In March 2026, the University of Alabama warned that faculty and staff were getting text messages that appeared to come from benefits@ua.edu. The texts claimed the recipient's 2026 compensation had been updated and asked them to review and confirm it through a link 4. UA noted that its HR office never discusses compensation or benefits by text. It also pointed out that tax season makes these lures more convincing, because people are already expecting financial paperwork 4.
A month later, Seton Hall University passed along an alert from New Jersey's state cybersecurity cell, NJCCIC. The alert described emails posing as updated compensation records or salary adjustments 2. Those messages used QR codes and counterfeit login pages to harvest credentials. Seton Hall cautioned that the techniques, though aimed at employees, are easily repurposed against students and others 2. The alert also described the campaign as part of a broader trend across New Jersey organizations, not just universities 2.
By late August 2026, Texas A&M reported a sustained rise in both email phishing and smishing 1. Two features of its advisory show how the tactics have developed:
- Phishing from real university accounts. Some messages came from compromised TAMU accounts posing as the Dean of Students or Faculty Affairs. They cited conduct complaints, Title IX matters, or misconduct reports to pressure recipients 1.
- Texts about jobs, pay, and benefits. These included fake research assistant offers, payroll problem notices, and urgent HR requests, all steering people away from official systems 1.
The Texas A&M emails linked to documents, often hosted on Google Drive, and then asked users to "install software" to view them 1. The university was direct about this: no campus office will ever make that request 1.
Why universities are such good targets
The sources agree on the underlying mechanics even where details differ. Every campaign depends on urgency and on institutional authority, whether a payroll office, a dean, or HR. Universities offer plenty of both. Staff are used to frequent administrative messages, many offices send them, and HR platforms like Workday are reachable from anywhere with a login.
There is also a notable resemblance between Storm-2657's "investigation" lures 3 and Texas A&M's Title IX and misconduct lures 1. Both invoke disciplinary or compliance matters that people are reluctant to ignore and may hesitate to ask colleagues about. That reluctance is exactly what attackers want, because it keeps victims from verifying before they click.
The move toward SMS deserves attention too. Alabama and Texas A&M both reported text-based attacks 14. Texts arrive on personal devices, outside the email filtering that institutions control, which makes this a channel defenders have trouble covering.
The takeaway
It would be easy to treat the Storm-2657 disclosure as a single incident. A more realistic reading is that it documented an early, organized version of a scheme that has since become common across campuses, whoever is running each new wave. The payoff is direct, the lures are cheap to produce, and seasonal timing around tax season or annual compensation updates gives attackers a reliable pretext.
For staff, the practical advice from these institutions overlaps heavily:
- Be suspicious of any unsolicited message about pay changes.
- Never scan a QR code or install software to view a document.
- Reach HR or payroll systems by typing the address yourself, not through a link.
- Remember that an email can come from a genuine university account and still be malicious 124.
For institutions, the lesson is that payroll and HR systems should be protected like the financial infrastructure they are.
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.