According to Weill Cornell Medicine's Notice of Email Phishing Incident, the organization learned on September 13, 2021 of suspicious email activity and identified unauthorized access to a small number of employee email accounts between September 9 and September 23, 2021. The notice states the access occurred as part of an effort to perpetuate phishing attempts, not to access patient information. The incident was limited to email. Electronic medical records were not accessible. Patient notification letters began November 12, 2021. Public reporting does not establish the exact phishing kit, credential-theft path, or pre-incident MFA coverage on those mailboxes.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers get into Weill Cornell employee email accounts?

Attackers obtained unauthorized access to a small number of Weill Cornell Medicine employee email accounts between September 9 and September 23, 2021 as part of phishing attempts, according to the organization's official notice. Weill Cornell learned of the suspicious email activity on September 13, 2021. Public reporting does not establish the exact phishing page, whether codes or push approvals were relayed, or any named MFA-bypass method. The documented fact is workforce mailbox access driven by phishing, not a published technical kit name.

Was the Weill Cornell electronic medical record system breached?

No. Weill Cornell Medicine stated this incident was limited to email, and Weill Cornell's electronic medical records were not accessible. What was at risk was residual patient information that already lived inside the compromised employee mailboxes, not a live EMR takeover. The organization assessed the goal as further phishing rather than deliberate patient-data targeting.

What patient data could have been exposed in the Weill Cornell email phishing incident?

Possible exposure in the affected employee email included patient name, address, email, date of birth, health insurance information, medical record number, and/or clinical information, with Social Security numbers in limited instances, according to Weill Cornell Medicine's notice. The organization said the incident affected only a small percentage of Weill Cornell patients; the official notice does not publish an exact patient count. Some breach databases list roughly 25,697 records, which is not stated on the official notice. Weill Cornell reported no indication that patient information was misused. Credit monitoring was offered where an SSN was involved.

Did multi-factor authentication fail at Weill Cornell in September 2021?

Public reporting does not establish whether MFA was enabled on the specific employee mailboxes that were accessed, or which factors those accounts used. The official notice only describes post-incident work: expanding security measures such as requiring all devices to use multi-factor authentication, plus more employee training on suspicious email. A phished secret that opens a mailbox is a credential-phase failure when login still accepts transferable factors. Once those sessions existed, residual PHI already in the mail was readable without a second login. MFA does not retract mailbox content after authentication has already succeeded.

What did Weill Cornell change after the employee email phishing incident?

After the incident, Weill Cornell Medicine stated it was continuing to expand extensive security measures, such as requiring all devices to utilize multi-factor authentication, and providing additional employee training on how to identify and avoid suspicious emails. Patient notification letters began November 12, 2021, with a dedicated call center. A fix for phishable workforce login paths exists; the prevention write-up is on the companion site, not in this what-happened post.