Skip to content
NetarxImpact Database
MFA Fatigue / Push BombingNo AI reportedConfirmed

Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients

Michigan Medicine (University of Michigan) · Healthcare · United States · July 30, 2024

People or records affected
57,891
58K as reported

What happened

Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.

How the deception worked

The attacker already held the employee's password and needed only the second factor, so they triggered an authentication push to the employee's device. The employee approved it. That is the whole attack: no link was clicked and no page was visited, only a notification approved out of reflex or annoyance, which is why push-based MFA fails in a way that hardware keys cannot. With the account open, the attacker had ordinary access to a clinician's mailbox, where routine correspondence carries medical record numbers, diagnoses and treatment details for tens of thousands of patients. Michigan Medicine disabled the account, blocked the attacker's IP address and forced password resets.

The control that would have caught it· our reading, not a claim from the sources

Number matching or, better, phishing-resistant hardware authenticators remove the ability to grant access by approving a prompt, and staff need a clear instruction to report unexpected prompts.

Sources (2)

  1. Michigan Medicine notifies patients of health information breach
    Michigan Medicine·michiganmedicine.orgOpen ↗
  2. Michigan Medicine email breach exposes patient information
    Becker's Hospital Review·beckershospitalreview.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.