Submit News
UVA Health logo of UVA Health Submit News

Connect

 
10.15.2025

New Cybercrime Scam Impersonates HR: How to Protect Yourself

What Happened?

A cybercrime group called Storm-2657 has been targeting university employees to steal their paychecks. These attacks started in March 2025 and have affected at least three universities, with phishing emails sent to over 6,000 people across 25 institutions. The attackers are not hacking the payroll systems directly — they're tricking people into giving up access to their accounts.

How the Scam Works:

1. Phishing Emails: Attackers send fake emails that look like they’re official Human Resources notifications (e.g., from HR, organizational leadership, or health alerts).

2. Fake Login Pages: These emails link to fake websites that look like real login pages (e.g., Workday).

3. Credential Theft: When users enter their login info and MFA (multi-factor authentication) codes, the attackers steal their credentials.

4. Account Takeover: Using the stolen info, attackers log into the victim’s account.

5. Redirect Paychecks: They change the direct deposit settings so the victim’s salary goes to the attacker’s bank account.

6. Covering Their Tracks: They set up email rules to hide alerts from HR systems, so victims don’t notice the changes.

Sample #1: A legitimate email from Workday (Click to enlarge.)
Sample #1: A legitimate email from Workday (Click to enlarge.)

How You Can Protect Yourself

Here are some simple but powerful steps you can take to protect yourself (and UVA Health!) from this scam: 

 1. Only Approve Duo MFA Push Notifications That You Requested

2. Never Click Suspicious Links

Sample #2: A legitimate email from Workday (Click to enlarge.)
Sample #2: A legitimate email from Workday (Click to enlarge.)

 3. Watch for Emails with Urgent or Emotional Language

 4. Check Your Inbox Rules

 5. Review Your Duo MFA Settings

 6. Report Suspicious Emails

If you have any questions or concerns regarding an email that you have received, please do not hesitate to reach out to HIT Security by submitting a ServiceNow ticket.

Final Thoughts

These attacks don’t exploit flaws in systems like Workday — they exploit human trust and weak security setups. UVA Health has implemented technical controls to reduce the chances of this type of attack going through, however we all need to strive to avoid clicking on suspicious content. By staying alert and following the steps above, you can help protect yourself and UVA Health from becoming a victim.

Comments (0)

Latest News