Theregister Fraudsters Exploit Help Desks to Redirect Employee Paychecks
Article Content
Browse articles
In December 2025, fraudsters executed a simple attack that involved a help-desk call to redirect a physician's salary into their own account. This incident, investigated by Binary Defense's ARC Labs, highlights vulnerabilities in processes and human factors rather than technical flaws. As a result, every employee is considered a potential target for similar attacks.
Ask AI about this cluster
Answers cite the sources they use
Updated 193d ago How this analysis works
Timeline
2025-12-01
Fraudulent help-desk call initiated
2025-12-01
Physician's salary redirected to fraudster's account
2026-02-11
Articles published detailing the incident
More articles in this cluster (4)
Following this threat?
Track Workday in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…