Security research published in October 2025 documented targeted attacks against United States universities in which attackers used compromised staff accounts to modify direct deposit details within HR self-service systems, redirecting salary payments.
This Is One Of Very Few Files With An Immediate Cash Outcome
The corpus struggles throughout to connect exposure to harm — the unbridged evidence problem at 25-1219, where no mechanism traces a fraud back to a breach.
Here the chain is complete and short. An account is compromised, a bank account field is changed, and a salary lands somewhere else on payday. No intermediary market, no resale, no waiting.
It sits with the business email compromise at 25-0602 and the recruited support agents at 25-0514 in the small set of files where the corpus can see the whole path.
The Victim Is The Employee, Not The Institution
That distinction determines everything about the aftermath. A university discovering redirected payroll has suffered an incident; an employee who was not paid has suffered a loss on a specific date with immediate consequences — rent, childcare, debt.
The corpus filed at 25-0704 that an employee is the most constrained data subject in this database: unable to decline giving their employer a bank account, unable to leave over a breach without leaving their job. This is that position producing a direct financial loss.
Self-Service Was The Design Decision
HR self-service exists so employees can update their own details without an administrative request. It removes cost and delay, and it is the reason a compromised account can change a payment destination without anyone approving it.
This desk filed the same trade at 25-0813 for MFA enrolment: the operation that establishes a durable outcome is administratively trivial, while noticing it requires somebody to look. A bank account change is exactly that shape.
And The Control Is Obvious And Unpopular
Out-of-band confirmation of any change to payment destination — the same measure this desk recommended for invoice fraud at 25-0602 — plus a mandatory delay before the first payment to a new account.
Both are cheap. Both produce complaints from employees who genuinely changed banks, which is why neither is standard.
Compiled from published vendor security research, listed below. Affected institutions and amounts are not enumerated in the material we reviewed. Corrections: corrections@forensicpost.com.