Phishing Attacks Threaten HR/Payroll Data: Query Manager Protects

July 01, 2017
Written by Danielle Larocca

Senior Vice-President of HCM Solutions Danielle Larocca has worked in the SAP HCM space for over 20 years. An SAP Mentor and featured speaker at numerous conferences, Danielle has authored four best-selling books on SAP, is the Technical Editor for the SAP Professional Journal, and often the Voice of the Expert on SAPInsider’s Ask the Expert series for HR.

Hackers target payroll vulnerabilities with phishing attempts

It seems like I read about another large online hack, malware or phishing scheme nearly every week. These days, not even HR and payroll departments are immune to these attacks. In one recent case, several universities experienced a phishing attack where the perpetrators sent mass emails to employees posing as a member of the Human Resource department. The email asked the employee to “confirm” their payroll and direct deposit banking information, and contained a link to a bogus site where the employee was asked to enter the data. The ultimate goal of the hackers was to access employee payroll direct deposit accounts.

According to a recent study by specialist insurer Beazley, there has been a dramatic increase in phishing scams aimed at employee tax information. Those scams represent 9% of all breaches Beazley handled in the first quarter of 2017. Beazley also found that the higher education sector has increasingly become a target, accounting for 48% of data breaches in Q1 2017 alone.

One customer’s proactive solution

Recently, one of our customers in the education sector fell victim to this type of attack. Several employees followed a phishing scheme’s instructions, and the perpetrators were able to capture the employees’ ESS login information as well as the bank account information before rerouting the direct deposit to their own bank accounts. This caused the complete loss of several employees’ pay checks.

Rather than being deterred, that clever customer instead focused on finding a way to help identify and prevent this type of phishing attack in the future. The customer already offered a custom Account Alert solution for ESS-related changes, but not all employees had enrolled. So, in addition to a new two-factor authentication process, they wanted to monitor changes made to employee banking information in ESS. Unfortunately, SAP standard reports didn’t meet their needs, so they created a custom Z-table to capture ESS changes to the Bank Information Infotype (0009) and then used EPI-USE Labs’ Query Manager™ to generate a regular report to display the data.

Query Manager provides access to HR, payroll and custom table data

Creating reports that combine master data, payroll data and Z-tables is not something you can do via the Ad Hoc Query or SAP Query reporting tools. The advantage of using Query Manager in this case was the ability to easily add the new custom Z-table, and combine that data with both HR Master data (PNP database) as well as payroll data from the PCL2 cluster. The resulting report is run right after payroll closes each pay period. Since deployment, the customer has prevented additional phishing incidents from successfully stealing an employee’s pay. While it is a manual process to review the ESS data, they were fortunate that they did not have that many direct deposit changes.

This report referenced a Z-table so it is unique to this customer, but the principle can be applied to other types of phishing incidents in the future. This is simply another example of a clever customer leveraging the tools at hand to solve business challenges.

Learn more about SAP reporting

 

 

Explore Popular Tags

Query Manager SAP SuccessFactors SAP HCM reporting SAP HCM HCM Reporting SAP Reporting SAP Payroll HCM SAP SuccessFactors Employee Central Payroll EPI-USE Labs SAP SuccessFactors Reporting reporting PRISM Payroll Document Builder Intelligent HR and Payroll Payroll reporting Query Manager Analytics Connector SAP Analytics Cloud Human Capital Management (HCM) SAP HCM Data SAP Query Microsoft PowerBI SAP SuccessFactors People Analytics SAP Payroll data Variance Monitor HR and Payroll data Tableau HXM Move Payroll Data SAP HCM Payroll SAP HR Reporting SAP HXM SAP S/4HANA SAP S/4HANA Private Cloud Edition (S/4 PCE) people analytics sap query hr Data Sync Manager Employee Central Payroll Journey to SAP SuccessFactors SAP SAP ERP HCM SAP HCM On-Premise Solutions SAP HCM journey SAP and SuccessFactors HXM Reporting COVID-19 Cloud-based SAP HCM solutions Employee payroll HCM Productivity Suite HR PRISM for HCM (Private Cloud Edition) PRISM free assessment SAP HCM/HXM SuccessConnect reporting solution ABAP DSM for HCM Employee Central Payroll Reporting Employee data GeoClock H4S4 Let's Talk HCM Pay Recon SAP Data Warehouse Cloud SAP HCM Analysis SAP SuccessFactors HCM Journey SAP SuccessFactors Roadmaps SAP data privacy and compliance SuccessFactors Ultimate Guide: SAP HCM & Payroll Options data validation payroll control center Artificial Intelligence (AI) Data Sync Manager for HCM Digital transformation Employee Central GDPR HCM, HR OData On-Premise Payroll Query Manager with Document Builder Real-time reporting and document creation SAP Analytics Cloud (SAC) SAP HCM On-premise SAP HCM for SAP S/4HANA On-Premise SAP HR SAP On-Premise customers SAP Payroll to the Cloud SAP Road maps SAP customers SAP data SAP data privacy & security Success Factors SuccessConnect 2019 Tax Reporting Transformation without re-implementation accurate payroll data certification custom infotype data source ebook on-premise SAP HCM s/4HANA Analytics solutions Automated reports Automation Cloud migrations DSM Object Sync for SuccessFactors Hybrid Data Secure Data Types Data analysis EPI-USE Labs’ solutions Employee Letters Employee communication Free HCM Assessment HR Journey HR employee reports Human Experience Management (HXM) Human Resources Human Resources data Hybrid Reporting SAP and SuccessFactors Hybrid SAP and SuccessFactors Hybrid reporting Hybrid reporting solution Integrated reporting SuccessFactors SAP Intelligent Enterprise Machine Learning (ML) Microsoft Excel News OData integration OM Object Sync On-Premise Payroll S/HANA Sidecar On-premise reporting Organization of the data PA PRISM for ECP PRISM for H4S4 People Analytics Workforce Planning Personalized documents Protect personal employee data Report Stories Reporting and analysis Robotic Process Automation (RPA) Robotic Process Automation framework S/4HANA Private Cloud Edition (PCE) SAP Data Privacy Suite SAP Data Security SAP ERP Payroll customers SAP HCM 2023 SAP HCM Roadmap SAP HCM and Payroll customers SAP HCM for S/4HANA SAP HXM 2021 SAP Mentors SAP SuccessFactors Hybrid SAP SuccessFactors Next-Gen Payroll SAP SuccessFactors Release updates SAP SuccessFactors Time Management SAP SuccessFactors Time Tracking SAP Wage Type Reporter SAP certified solution SAP migration SAPPHIRE 2018 SuccessFactors and the Intelligence Enterprise SuccessFactors' Employee Central Payroll TCO Calculator The Report Center The Road to People Analytics Time management Workforce Planning ad hoc data variances easy reporter high-speed, low-risk on-premise SAP data partner roadmap single reporting solution sq01 stories in SAP SuccessFactors People Analytics technology third party AI ALE STP report ASUG Accessing COVID-19 data Ad Hoc Query American Payroll Association (APA) Analytics Connector Analytics reports Analytics solution At-risk employees Australian Payroll Australian Tax Office (ATO) Automated analysis and pay run reconciliations Automatic HR reports BTP Best practice in BI Bots Business Analytics Business Intelligence COVID-19 statistics COVID-19 vaccinations Certified solutions ChatGPT Check for data replication errors Client Sync Cloud hosting SAP PCE Company Branding Compare legacy HR and Payroll data Comparing data Configuration Center Copy and mask test data Coronavirus Created timestamp Custom store Customer-specific infotypes DSAG Data Privacy Data Replication Data Sources Data Sync Manager (DSM) Data access Data privacy regulations Data production support issue solution Democratize data Description Diversity & Inclusion reporting DocuSign Document Building Dubai Dynamic data ECC EPI-USE ERP Education sector Electronic Signatures Embedded Analytics Edition Employee Central time Employee Central timesheets Employee NICs Employee Retention Analytics (ERA) Employee payment summaries Employee right to privacy Employer NICs Encrypt data FAQ Index Font Guidelines Gender Pay Gap
+ See More

Get Instant Updates


Leave a Comment: