In January 2021, Western Michigan University Homer Stryker M.D. School of Medicine (WMed) lost control of a single employee email account after a phishing click. According to MLive, the unauthorized access window ran from 11 to 21 January 2021 and led to notices for roughly 2,474 employees and beneficiaries whose information, including Social Security numbers, sat in that mailbox. A related Montana Attorney General notice documents the same workforce-notification path. Public reporting frames credential-phase email phishing and a planned fall 2021 two-factor rollout. It does not name AiTM, a spoofed reverse-proxy kit, device-code flow, helpdesk recovery, or an MFA bypass at the time of the click.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
How did attackers get into the WMed employee email account?
The WMed incident began when an employee clicked a phishing link and attackers then gained unauthorized access to that one employee email account. According to MLive reporting on the school’s warning, the access window ran from 11 January 2021 through 21 January 2021. Public reporting does not establish an adversary-in-the-middle proxy, session-cookie theft as a separate initial vector, device-code phishing, or helpdesk re-enrollment. The documented path is workforce email phishing that produced a usable mailbox login for a single account.
Was MFA protecting that WMed mailbox when the phishing attack hit?
Public reporting does not establish that two-factor authentication was live on the compromised WMed employee mailbox at the time of the January 2021 click. MLive reported that WMed said it was already working toward two-factor authentication, with a fall 2021 rollout planned. That is an MFA gap signal, not a documented bypass of a deployed second factor. Password-only or otherwise phishable sign-in is enough for a stolen secret to complete login before any stronger control arrives.
What data left the WMed mailbox, and how many people were notified?
With the WMed employee mailbox already open, attackers could read message content that exposed employee and beneficiary information, including Social Security numbers. Contemporaneous reporting puts notices at roughly 2,474 employees and beneficiaries. That exposure is post-authentication data access inside an already-opened session. MFA does not unread mail that was already viewed after sign-in succeeded.
Did limiting the breach to one WMed mailbox contain the real harm?
Limiting initial access to one WMed employee email account still left a high-value inbox full of identity data. The harm was not lateral movement across dozens of accounts in public reporting. It was the contents of that single workforce mailbox: employee and beneficiary details, including Social Security numbers, for about 2,474 notified people. One phished corporate mailbox is enough when HR, benefits, and identity paperwork flow through email.
Would stronger authentication have changed the WMed outcome?
Closing the phishable login stops this path. A phishing-proof, device-bound control on workforce email would have blocked attacker sign-in even after the phishing click stole a secret, because there is no transferable password or OTP for the attacker to replay at the real login. Public reporting does not claim malware on the endpoint after a legitimate session. Mail already read after a successful attacker login is a separate, harder problem. A fix for the credential-phase gap exists; the companion prevention piece covers that angle without treating user caution as the control.