Phishing put attackers inside Mon Health contractor and employee mailboxes for a multi-month window. According to Mon Health's 21 December 2021 website notice, unauthorized email access ran from 10 May 2021 to 15 August 2021. Discovery came on 28 July 2021 when a vendor flagged a missed payment and fraudulent wire-transfer attempts. The same notice links the incident to about 398,000 patients and states intent to implement MFA for remote access to email. Public reporting does not establish the phishing capture method, whether remote email already required MFA before the incident, or whether any fraudulent wires succeeded.
If you want the prevention angle on workforce remote-email login, read the related article on mfa2point0.com.
FAQ
How did attackers get into Mon Health email accounts?
Attackers got into Mon Health contractor and employee email through phishing that compromised those workforce accounts. Public reporting does not name an AiTM kit, device-code flow, helpdesk TAP, or other capture detail. What is documented is credential-phase email account takeover: phished access to mailboxes, not a separate malware or session-cookie story as the entry path.
How long did unauthorized Mon Health email access last, and how was it found?
Unauthorized access to the compromised Mon Health contractor and employee mailboxes began on 10 May 2021 and continued through 15 August 2021 per the investigation window. Mon Health discovered the incident on 28 July 2021 after a vendor reported a missed payment and fraudulent wire-transfer attempts. That tip, not an internal login alarm described in the public notice, is what surfaced the BEC activity.
Did the Mon Health breach expose about 398,000 patients, and what data left the mailboxes?
Mon Health's notice and related reporting tie the incident to about 398,000 patients. Public reporting does not inventory which patient data element types sat in the compromised contractor and employee mail, or prove bulk exfiltration beyond unauthorized mailbox access that supported BEC and wire-fraud attempts. Once those mailboxes were open, reading mail and staging payment fraud did not require a fresh login on every message.
Did Mon Health have MFA on remote email before the phishing?
Public reporting does not establish that Mon Health required MFA for remote email before the 2021 phishing. The December 2021 website notice states intent to implement MFA for remote access to email after the fact. That post-incident plan is a control gap signal, not proof of a specific pre-incident bypass technique.
Would MFA on remote email have stopped the Mon Health BEC and wire-fraud attempts?
MFA aimed at remote email would have mattered on the login surface that opened the contractor and employee mailboxes, not on undoing mail already read or payment instructions already sent. Closing a phishable remote-email login stops repeated sign-ins with stolen workforce credentials across a window like May through August 2021. After account takeover, BEC content and fraudulent wire attempts are downstream of an open mailbox; no MFA retracts that phase. Public reporting does not establish whether any of those wires completed.