[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbYrwu1bLivKnOQEdSr6R2CxNMJJFnIy_GbWAs-0C3Cc":3},{"article":4,"iocs":48,"watch_terms":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"51bc467f-3973-4b02-bfb0-1563b7a66aec","Incident response for AI: Same fire, different fuel","incident-response-for-ai-same-fire-different-fuel-e827d6","AI changes how incidents unfold and how we respond. Learn which IR practices still apply and where new telemetry, tools, and skills are needed. The post Incident response for AI: Same fire, different fuel appeared first on Microsoft Security Blog.","Microsoft's Incident Response and Detection team discovered Storm-2755, a financially motivated threat actor compromising Canadian employee accounts to steal salary payments. The group targets employee profiles and redirects payroll to attacker-controlled accounts. This incident highlights evolving IR practices needed to detect and respond to AI-era threats with new telemetry and skills.","Microsoft DART identifies Storm-2755 threat actor targeting Canadian employees for payroll theft.","April 9 12 min read Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees Microsoft Incident Response – Detection and Response Team (DART) researchers observed an emerging, financially motivated threat actor, tracked as Storm-2755, compromising Canadian employee accounts to gain unauthorized access to employee profiles and divert salary payments to attacker-controlled accounts.","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F04\u002F15\u002Fincident-response-for-ai-same-fire-different-fuel\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F03\u002FMS_Actional-Insights_Adversarial-AI.png","2026-04-15T16:00:45+00:00","2026-04-15T18:00:21.024613+00:00",7,[18,21,24],{"name":19,"type":20},"Storm-2755","threat_actor",{"name":22,"type":23},"Microsoft","vendor",{"name":25,"type":26},"Incident Response and Detection and Response Team (DART)","technology","c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73",{"id":27,"icon":29,"name":30,"slug":31},null,"Incident Response","incident-response",[33,38,43],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":44},{"id":45,"icon":29,"name":46,"slug":47},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[49],{"type":42,"value":19,"context":50},"Financially motivated threat actor targeting Canadian employees for payroll diversion",[22]]