According to the California OAG breach notice for the Los Angeles County Department of Mental Health, around 20 March 2024 an employee opened a phishing email with a QR-code attachment, scanned it, and reached a malicious site that enabled takeover of their Microsoft 365 account. County notices describe an MFA credential reset and say Microsoft was notified of an MFA vulnerability exploited in the attack. Public reporting does not establish a named threat actor, a quantified PHI record count, or the exact MFA bypass mechanics beyond that county attribution.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers get into LA County DMH Microsoft 365?

Attackers accessed a Los Angeles County Department of Mental Health Microsoft 365 account after an employee scanned a QR code from a phishing email attachment and visited a malicious site around 20 March 2024. According to the California OAG breach notice, that path enabled account takeover. County notices also describe an MFA credential reset in connection with the incident. Public reporting does not establish lateral movement beyond that employee mailbox path.

What MFA weakness did county notices actually claim?

County notices for the LA County DMH incident state that Microsoft was notified of an MFA vulnerability exploited in the attack, and they describe an MFA credential reset. Public reporting does not establish a CVE, a product defect name, or a step-by-step second-factor harvest technique beyond that attribution. The documented shape is still credential-phase: something usable at login after the QR-delivered malicious site, not a separate post-login malware story in the notice text available here.

Was PHI exposed, and how many records?

County notices describe PHI exposure related to workforce Microsoft 365 mailbox access after the account takeover. Public reporting does not establish a quantified record count for the LA County DMH incident. Once the mailbox session existed, reading mail was ordinary post-authentication access. MFA does not re-check every message open after a live session is already in attacker hands.

Was this helpdesk vishing, device-code phishing, or a named AiTM kit?

No. Public reporting on the LA County DMH breach describes a phishing email with a QR-code attachment, a malicious site, and Microsoft 365 account access with an MFA weakness cited by the county. It does not establish helpdesk password or TAP resets, OAuth device-code coaching, a named reverse-proxy kit brand, or a named threat actor. Treat those as other industrial playbooks unless a primary notice names them for this case.

Would stronger MFA have stopped the initial takeover?

Closing the phishable login stops this path. County notices already point at MFA as part of what went wrong at access time, so the failure sits on transferable login factors a malicious site can abuse, not on “MFA is useless after tokens exist.” A fix exists that removes those transferable secrets from workforce login; the prevention write-up is on the companion site. Mailbox access after a session already exists is a harder, separate problem, and revoke remains hygiene there.