According to Okta's Newsroom on 15 December 2025, threat cluster O-UNC-034 (the payroll pirates) socially engineered IT helpdesks by phone, reset employee passwords, re-enrolled attacker-controlled MFA factors, then altered payroll banking in HR apps across a multi-organization cluster. Okta Threat Intelligence had detailed the pattern in an advisory dated 29 September 2025. Public reporting does not name victim companies, dollar losses, or a fixed org count beyond that multi-org cluster. The same helpdesk-reset class showed up earlier in 2025 in the M&S helpdesk password-reset case.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did the O-UNC-034 payroll pirates get into workforce accounts?

The O-UNC-034 payroll pirates got in by phoning IT helpdesks and socially engineering password resets for employee accounts, then enrolling MFA factors the attackers controlled. According to Okta's December 2025 Newsroom reporting on the cluster, those factors included paths such as Okta Verify, SMS, voice, and security questions after the reset. Once the password and second factors sat under attacker control, later logins no longer needed another helpdesk call.

Why didn't existing MFA stop the payroll pirates takeover?

Existing MFA did not stop O-UNC-034 because the attackers replaced the legitimate second factors after the helpdesk password reset. Legacy recovery treated a phone conversation plus weak caller identity proofing as enough to issue a new password and open factor enrollment. That is a credential-phase failure at recovery, not a bypass of cryptography after a finished login. Public reporting does not establish that reverse-proxy phishing kits or Temporary Access Passes were the mechanism in this cluster.

What happened after attackers controlled the employee accounts?

After O-UNC-034 controlled workforce accounts, attackers changed employee payroll banking information in HR and payroll applications such as Workday, Dayforce, or ADP so paychecks could be diverted. MFA does not undo in-app authorization abuse once someone authenticates as the employee. Stopping payroll siphoning depends on blocking the earlier helpdesk recovery takeover, plus HR-side controls outside authentication. Public reporting does not establish quantified paycheck totals for the cluster.

Is helpdesk vishing different from coaching a user through a fake login?

Helpdesk vishing for a password reset and MFA re-enrollment is the same social-engineering class as coaching a user through a fake login. In both paths a human is talked into handing over a transferable factor. For the O-UNC-034 payroll pirates cluster, that path was helpdesk recovery and attacker factor enrollment. A fix that removes phishable recovery secrets and blocks factor replacement on weak phone proofing alone stops both paths; the companion post covers prevention without rehashing the incident chronology.

Did this campaign hit only one industry or one company?

No. Okta framed O-UNC-034 payroll pirates activity as a multi-organization workforce-identity cluster, with cross-sector exposure that includes education, manufacturing, retail, and pharma/healthcare in the campaign framing. Public reporting does not establish named victim organizations or a precise headcount of affected employers beyond the multi-org cluster description.