Aramark employees phished through fake myPay site in payroll diversion scheme

Organization
Aramark
Exploit
Phishing
Industry
Food Services

Aramark, the Philadelphia based food service and facilities management company, notified current and former employees in September 2024 that a credential phishing scheme had exposed their personal information. In a filing made to the Maryland Attorney General's Office by outside counsel on September 13, 2024, the company said it had learned on or about August 22, 2024 that a bad actor had built a website designed to imitate the Aramark myPay portal.

The fake site was used to capture employee usernames and passwords. Aramark said that in what it described as a relatively small number of cases the attacker used those credentials to log in to the genuine myPay site and change direct deposit details so that wages would be routed to another bank account. The company characterised the activity as part of a wider campaign against organisations using myPay and similar payroll services.

Where credentials were used successfully, the attacker may also have viewed first and last names, addresses and Social Security numbers. Aramark said there was no indication the data had been used for any purpose beyond redirecting pay.

Notification letters went out on September 10, 2024 and offered two years of Experian IdentityWorks monitoring and identity restoration. Aramark did not disclose a companywide total; the Maryland filing covered five state residents. The company said it was working with industry partners to help prevent further fake myPay sites.

Sources