On July 30, 2024, a Michigan Medicine employee accepted an unsolicited multifactor authentication prompt. According to CBS Detroit, citing Michigan Medicine’s release, that approval allowed a cyberattacker to access the employee’s email account and its contents. The emails were job-related treatment and coordination traffic. A later review found they could include patient names, medical record numbers, diagnostics, and treatment information. Michigan Medicine began mailing notices around September 26, 2024 covering about 57,891 patients. Public reporting does not establish how the attacker first obtained the password or login context that triggered the prompt, and it does not name a threat actor.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
How did attackers get into Michigan Medicine email in July 2024?
Attackers reached a Michigan Medicine employee mailbox after the employee accepted an unsolicited multifactor authentication prompt on July 30, 2024. According to Michigan Medicine’s release as reported by CBS Detroit, that approval allowed the cyberattacker to access the employee’s email account and its contents. The account was disabled as soon as possible, the attacker IP was blocked, and passwords were changed. Public reporting does not establish how the attacker first obtained the password or the login context that caused the prompt to appear.
Was the July 2024 MFA approval the same as Michigan Medicine’s May 2024 breach?
No. Michigan Medicine patients were also impacted by a data breach in May 2024, and CBS Detroit framed the July event as a second cyberattack. The July path is workforce email access after an employee accepted an unsolicited MFA prompt. Sources treat that as distinct from the earlier May incident, which intake and related reporting describe as helpdesk-related rather than prompt-approval failure. Do not collapse the two into one story.
What patient information was at risk after the Michigan Medicine MFA approval?
About 57,891 patients were notified that health information was possibly exposed after the July 30, 2024 email compromise. Michigan Medicine said the involved emails were job-related communications for treatment and coordination. Contents could include patient names, medical record numbers, diagnostics, and treatment information. Public reporting does not establish exposure of Social Security numbers, bank account numbers, or payment card data. The organization also said it found no evidence the attack aimed to gain health information, but data theft could not be ruled out.
Why didn’t multifactor authentication stop the Michigan Medicine email breach?
Multifactor authentication did not stop the July 2024 Michigan Medicine email breach because the compromise followed the employee’s acceptance of the unsolicited MFA prompt itself. Once a human approved that prompt, authentication completed for whoever had initiated the sign-in, and the attacker held mailbox access. After that session existed, MFA could not recall messages already opened or undo the access path. Containment was account disablement, IP blocking, and password changes, not another prompt. Coachable approve-a-prompt MFA fails this class of social pressure at the credential phase; a fix that removes the transferable approval step exists, covered on the companion prevention post.
What did Michigan Medicine change after the July 2024 prompt-approval incident?
According to Michigan Medicine via CBS Detroit, the organization moved to decrease how long emails are retained, modify identity verification processes used to access Michigan Medicine systems, and increase education on multifactor authentication use. The employee was subject to disciplinary action. Public reporting does not name a specific threat actor or group, and it does not publish a full technical breakdown of the MFA product or how many prompts were sent before approval.