Phishing opened UC San Diego Health employee email for months. According to the California Attorney General sample individual notification tied to a 27 July 2021 substitute notice, unauthorized access to workforce mailboxes ran in a continuous window from 2 December 2020 through 8 April 2021, and personal information may have sat in those accounts. Reporting cites roughly 495,949 individuals potentially exposed. Public reporting does not establish MFA enrollment, any second-factor failure method, AiTM tooling, helpdesk recovery abuse, or how many mailboxes were taken over. The documented story is phishing-driven workforce mailbox takeover, then post-login reading of whatever those inboxes already held.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers get into UC San Diego Health employee email?

Attackers reached UC San Diego Health employee email through phishing that led to unauthorized access to workforce mailboxes. Public reporting and the California AG sample notice describe phishing-driven compromise of employee email, not a named Exchange exploit, device-code flow, or helpdesk reset. Public reporting does not establish whether victims typed only a password, completed a second factor, or hit a proxied login page. What is documented is unauthorized mailbox access after that phishing path succeeded.

How long did unauthorized mailbox access last at UC San Diego Health?

Unauthorized access to UC San Diego Health employee email accounts ran in a continuous reported window from 2 December 2020 through 8 April 2021. That is more than four months of potential dwell on compromised workforce mailboxes before the window closed. Public reporting does not establish per-account dwell time or the exact count of mailboxes involved. Archive coverage often anchors on March 2021 as the mid-point of that multi-month access period.

What personal information may have been exposed in the UC San Diego Health email breach?

Reporting cites roughly 495,949 individuals potentially exposed through compromised UC San Diego Health employee mailboxes. The California AG sample individual notification confirms unauthorized mailbox access and lists categories of personal information that may have been present in those accounts. Public reporting does not establish a clean inventory of every field actually viewed or taken from each mailbox. Exposure risk rode on whatever PHI, identifiers, or other personal data employees had already received or stored in email.

Did public reporting document MFA on the UC San Diego Health mailboxes?

Public reporting does not establish that MFA was enrolled on the affected UC San Diego Health employee email accounts, and it does not name any second-factor failure path. The AG notice and related coverage do not name push fatigue, OTP relay, AiTM session capture, SIM swap, or helpdesk re-enrollment. Calling this a proven second-factor failure invents detail the sources do not support. The honest description is phishing-driven unauthorized access to workforce email with MFA status unspecified.

Did any MFA stop attackers from reading mail after login succeeded?

No MFA stops an attacker from reading UC San Diego Health mailbox content after authentication has already succeeded and a live session exists. Prevention value sits upstream, at the phishing login that should never have completed. Closing a phishable workforce email login shrinks this account-takeover class. Revoking sessions and rotating credentials after the fact is containment, not a rewrite of post-login mailbox exposure.