{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5"},"incident":{"slug":"2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5","title":"Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients","date":"2024-07-30","date_precision":"day","year":2024,"victim_org":"Michigan Medicine (University of Michigan)","sector":"Healthcare","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":57891,"threat_actor":null,"summary":"Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.","how_it_worked":"The attacker already held the employee's password and needed only the second factor, so they triggered an authentication push to the employee's device. The employee approved it. That is the whole attack: no link was clicked and no page was visited, only a notification approved out of reflex or annoyance, which is why push-based MFA fails in a way that hardware keys cannot. With the account open, the attacker had ordinary access to a clinician's mailbox, where routine correspondence carries medical record numbers, diagnoses and treatment details for tens of thousands of patients. Michigan Medicine disabled the account, blocked the attacker's IP address and forced password resets.","lessons":"Number matching or, better, phishing-resistant hardware authenticators remove the ability to grant access by approving a prompt, and staff need a clear instruction to report unexpected prompts.","confidence":"Confirmed","sources":[{"title":"Michigan Medicine notifies patients of health information breach","url":"https://www.michiganmedicine.org/news-release/michigan-medicine-notifies-patients-health-information-breach-3","publisher":"Michigan Medicine"},{"title":"Michigan Medicine email breach exposes patient information","url":"https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/michigan-medicine-email-breach-exposes-patient-information/","publisher":"Becker's Hospital Review"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5"}}