Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Passages

(2,812 posts)
Tue May 27, 2025, 08:20 AM Tuesday

Employees Searching Payroll Portals on Google Tricked Into Sending Paychecks to Hackers

May 27, 2025
Ravie Lakshmanan

Threat hunters have exposed a novel campaign that makes use of search engine optimization (SEO) poisoning techniques to target employee mobile devices and facilitate payroll fraud.

The activity, first detected by ReliaQuest in May 2025 targeting an unnamed customer in the manufacturing sector, is characterized by the use of fake login pages to access the employee payroll portal and redirect paychecks into accounts under the threat actor's control.

"The attacker's infrastructure used compromised home office routers and mobile networks to mask their traffic, dodging detection and slipping past traditional security measures," the cybersecurity company said in an analysis published last week.

"The adversary specifically targeted employee mobile devices with a fake website impersonating the organization's login page. Armed with stolen credentials, the adversary gained access to the organization's payroll portal, changed direct deposit information, and redirected employees' paychecks into their own accounts."
https://thehackernews.com/2025/05/employees-searching-payroll-portals-on.html?_m=3n%2e009a%2e3678%2eqb0ao44uux%2e2pho

Latest Discussions»Help & Search»Computer Help and Support»Employees Searching Payro...