Desk live·
ForensicPost
Cloud/Fraud/File 25-1009b

Compromised Accounts Used to Alter US University Payroll Deposits

Research published in October 2025 documented attacks against US universities in which compromised accounts were used to alter payroll direct deposit details in HR self-service systems.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS university employees
ActorUnattributed
D. Kennedy12 min readConfidence: high2 sources reviewed

Security research published in October 2025 documented targeted attacks against United States universities in which attackers used compromised staff accounts to modify direct deposit details within HR self-service systems, redirecting salary payments.

This Is One Of Very Few Files With An Immediate Cash Outcome

The corpus struggles throughout to connect exposure to harm — the unbridged evidence problem at 25-1219, where no mechanism traces a fraud back to a breach.

Here the chain is complete and short. An account is compromised, a bank account field is changed, and a salary lands somewhere else on payday. No intermediary market, no resale, no waiting.

It sits with the business email compromise at 25-0602 and the recruited support agents at 25-0514 in the small set of files where the corpus can see the whole path.

The Victim Is The Employee, Not The Institution

That distinction determines everything about the aftermath. A university discovering redirected payroll has suffered an incident; an employee who was not paid has suffered a loss on a specific date with immediate consequences — rent, childcare, debt.

The corpus filed at 25-0704 that an employee is the most constrained data subject in this database: unable to decline giving their employer a bank account, unable to leave over a breach without leaving their job. This is that position producing a direct financial loss.

Self-Service Was The Design Decision

HR self-service exists so employees can update their own details without an administrative request. It removes cost and delay, and it is the reason a compromised account can change a payment destination without anyone approving it.

This desk filed the same trade at 25-0813 for MFA enrolment: the operation that establishes a durable outcome is administratively trivial, while noticing it requires somebody to look. A bank account change is exactly that shape.

And The Control Is Obvious And Unpopular

Out-of-band confirmation of any change to payment destination — the same measure this desk recommended for invoice fraud at 25-0602 — plus a mandatory delay before the first payment to a new account.

Both are cheap. Both produce complaints from employees who genuinely changed banks, which is why neither is standard.

How we reported this

Compiled from published vendor security research, listed below. Affected institutions and amounts are not enumerated in the material we reviewed. Corrections: corrections@forensicpost.com.

Sources
  1. Investigating targeted payroll pirate attacks affecting US universitiesMicrosoft Security
  2. Workday data breach 2025: what was exposed and how it happenedSecurity.org
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary