According to Michigan Medicine's consumer notification (Montana DOJ filing), between 23 and 29 May 2024 an attacker called the IT Service Desk, impersonated employees, and triggered password resets that compromised three workforce email accounts. The helpdesk issued new login credentials before any later mailbox prompt could matter. Public reporting does not establish mailbox contents, confirmed patient-data theft, ransom, or a threat actor, and it only notes a later patient-notice review without detailing scope or outcome.
This is the same industrial vishing class as coaching a user through a fake login: a live call that moves a transferable secret. A similar helpdesk password-reset path later hit Marks & Spencer. A fix exists for both paths. Do not conflate this May Service Desk event with a separate July MFA-prompt incident at the same organization.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
How did attackers get into Michigan Medicine employee email in May 2024?
The attackers got into three Michigan Medicine workforce email accounts by calling the IT Service Desk between 23 and 29 May 2024, impersonating employees, and triggering password resets. According to Michigan Medicine's consumer notification, those resets produced login credentials the attacker could use on the email accounts. Public reporting frames the vector as helpdesk password-reset social engineering, not day-one endpoint malware.
Did MFA get bypassed in the Michigan Medicine Service Desk incident?
Public reporting does not establish that Michigan Medicine MFA was defeated at a login form. The failure was upstream: the IT Service Desk accepted caller identity claims and completed password resets, handing the attacker new credentials. Once those reset passwords existed, signing into the three email accounts under the new credentials was ordinary access with attacker-held secrets, not a live OTP or push defeat on a proxied page.
Was this an AiTM kit, device-code flow, or session-cookie theft?
Public reporting does not name an AiTM reverse proxy, session-cookie theft, device-code OAuth, or Temporary Access Pass issuance in the Michigan Medicine May 2024 IT Service Desk event. The documented path is phone impersonation that triggered helpdesk password resets for three employee email accounts. Intake also states no device-code involvement.
Is the May helpdesk breach the same as Michigan Medicine's July MFA-prompt incident?
No. The May 2024 IT Service Desk password-reset impersonation is a distinct event from a separate July MFA-prompt incident at Michigan Medicine. Public materials used for this write-up instruct not to merge the two. Public reporting does not establish the July incident's date, impact, or technique in enough detail to analyze it here.
What actually failed at the Michigan Medicine IT Service Desk?
Identity proofing on the recovery call failed. The desk reset passwords for callers who claimed to be employees without phishing-resistant proof that the real account holder was on the line. That is the same social-engineering class as a coached fake login: live coaching of a transferable factor. Closing phishable recovery and helpdesk reset paths stops this route; planting malware after a legitimate login is a harder, separate problem.