Suspicious Workday Payment Election Change via Compromised Account (via workday)

PremiumReviewedSigma · Low · v1
Product
workday
Service
audit
Author
HuntRule
Published
2026-07-30
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule surfaces Workday audit events where an account modifies payment elections or core account details. This activity matches payroll pirate operations in which attackers who phished university credentials register their own MFA device and reroute direct deposit to attacker-controlled bank accounts. Correlating payment element changes with recent device enrollment helps surface payroll fraud before funds are lost.

Related detections3 linkedT1098.005 — drag to rearrange
Suspicious Device Registration Following OAuth Token Theft
Possible Rogue Device Registration in Entra ID After Device Code Phishing
Suspicious Exchange Online Mail Flow Rule or Connector Creation via Compromised Account
Suspicious Workday Payment Election Change via Compromised Account (via workday)
Pivot detection · T1098.005 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.