A breach at a cloud payroll provider has cascaded across its client base, exposing payroll data for employees at more than 600 companies and enabling fraudulent salary diversions at several.
Attackers gained entry through a compromised support administrator account, then accessed client tenants to view bank details, tax identifiers and salary information. In a subset of cases, direct-deposit details were altered to route salaries to mule accounts.
The provider has suspended payroll changes pending re-verification, reset all administrative credentials and engaged external incident responders. Affected employees are being offered credit monitoring.
The incident underscores concentration risk in business software supply chains, where a single vendor compromise can touch thousands of downstream organizations.
