A fake fax lure was enough. According to the NYDFS Healthplex Consent Order, on or about 22-23 November 2021 an employee typed business email credentials into a phishing site. Healthplex became aware on 24 November 2021 that the employee’s Microsoft Office 365 mailbox had been opened in a browser. MFA was not enabled for Outlook Web Access after the company’s O365 migration, so the actor signed in with the password alone and reached residual NPI sitting in mailbox content. NYDFS-related figures put the compromised mailbox on the order of roughly 130,000 emails, with related reporting citing on the order of about 89,955 members and tens of thousands of New York residents’ NPI exposed in that residual mail. Public reporting does not name a threat actor, establish a ransom, or document dwell-time length.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers get into the Healthplex Office 365 mailbox?

Attackers got into the Healthplex Office 365 mailbox after an employee entered business email credentials into a phishing site that used a fake fax lure on or about 22-23 November 2021. According to the NYDFS Healthplex Consent Order, MFA was not enabled for Outlook Web Access after Healthplex’s O365 migration, so the actor signed into the employee mailbox over a web browser with the stolen password alone. Healthplex became aware of the mailbox access on 24 November 2021.

Was MFA bypassed in the Healthplex breach?

No. Public reporting does not describe an MFA bypass in the Healthplex breach. MFA was not enabled for Outlook Web Access on the path the actor used, so there was no second factor to complete, fatigue, or relay. The failure was password-only external web mail after the O365 migration, not a defeated push, OTP, or FIDO ceremony.

What data was reachable after the Healthplex mailbox login?

After the password-only Outlook Web Access login, the actor could reach residual NPI already present in the compromised employee mailbox. NYDFS-related figures cite on the order of roughly 130,000 emails in that mailbox. Related reporting cites on the order of about 89,955 members, and intake summarizing NYDFS findings describes tens of thousands of New York residents’ NPI as accessible in mailbox content. Public reporting does not establish a single exact affected-individual headcount across every figure.

Did this Healthplex incident involve AiTM, device-code phishing, or token malware?

Public reporting does not establish adversary-in-the-middle reverse-proxy phishing, OAuth device-code phishing, session-cookie malware, or a named threat group for the Healthplex mailbox access. The documented path is credential phishing via a fake fax lure, then browser sign-in to Office 365 mail because MFA was not enabled on Outlook Web Access after migration.

Would turning on any MFA have changed the Healthplex outcome?

Requiring a real second factor on Outlook Web Access and other external Microsoft 365 mail paths would have stopped password-only browser access after the fake fax lure. Legacy OTP or push still leaves transferable codes and approvals that other campaigns abuse; a fix that removes phishable login factors exists, and the companion prevention piece covers that control choice. MFA does not scrub NPI already sitting in a mailbox after a fully authenticated session exists.