The newest payroll-diversion campaign is not a classic fake email story. It begins when an employee searches for a normal workplace login.
In public April 9, 2026 reporting, researchers described a financially motivated actor using SEO poisoning and malvertising to place malicious sign-in pages in front of Canadian employees. The campaign hijacked sessions, searched for payroll workflows, hid HR replies, and redirected salary payments.
The interesting part is the path from search result to paycheck. The attacker did not need to trick payroll first. They first became the employee.
How The Campaign Works
The lure starts with search behavior. Victims looking for common cloud login terms are routed to a malicious sign-in page. From there, an adversary-in-the-middle workflow captures credentials and session tokens, allowing the attacker to reuse an authenticated session without triggering the same MFA challenge the victim already completed.
After access, the attacker looks for payroll and HR process clues, then moves into fraud.
The Inbox Rule Is The Quiet Part
The campaign reportedly created inbox rules that moved messages containing words such as direct deposit or bank into hidden folders. That is a practical move. It keeps the victim from seeing the conversation that would reveal the fraud.
This is why payroll phishing is a workflow attack. The phish gets the session, but the fraud succeeds because normal HR communication is manipulated after the login.
Why MFA Was Not Enough
The campaign used adversary-in-the-middle behavior. The user completed the sign-in flow, but the attacker captured enough session material to continue as the user. In observed activity, suspicious non-interactive sign-ins and repeated token replay patterns were part of the signal.
Traditional MFA can reduce many risks, but it does not always stop a proxy that captures a completed session. That is why phishing-resistant MFA and session revocation matter after compromise.
What Defenders Should Change
- Watch the login source, not just the mailbox. Search-driven access to fake sign-in pages can start outside email entirely.
- Alert on payroll-related inbox rules. Rules that hide direct-deposit or banking messages should be treated as high-risk after account compromise.
- Revoke sessions after suspected AiTM compromise. Password reset without token cleanup may leave the attacker active.
- Require out-of-band verification for payment changes. HR and payroll teams need a trusted confirmation path that does not rely on the compromised inbox.
Where Secto Fits
This attack depends on a deceptive browser moment. The user believes they are logging into a normal workplace service, but the rendered page is part of a session-theft workflow.
- Secto focuses on the point where search traffic becomes a rendered workplace login page.
- That gives defenders browser-side visibility before the employee completes the dangerous interaction.
- Stopping the deceptive page early reduces the chance that one trusted-looking login becomes payroll fraud downstream.