According to GuidePoint Security around 27 August 2024, GRIT documented a US workforce campaign that targeted more than 130 organizations. Callers posing as IT or helpdesk sent SMS links to fake Cisco, Fortinet, or Palo Alto VPN login pages, harvested usernames and passwords with MFA one-time codes, and coached push approvals live on the phone. Public reporting does not name reverse-proxy AiTM kits, TAP issuance, threat-actor attribution, or the victim organizations.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

What did GuidePoint GRIT actually document in this VPN vishing wave?

GuidePoint GRIT documented a US campaign, publicly described around 27 August 2024, in which operators impersonated IT or helpdesk, texted SMS links to fake Cisco, Fortinet, or Palo Alto VPN login pages, and collected workforce usernames, passwords, and MFA material. According to GuidePoint reporting in the intake, more than 130 organizations were targeted across sectors. Campaign victims were mostly unnamed in public material, and public reporting does not establish ransom figures or confirmed breach-of-record counts beyond that target set.

How did attackers get passwords and MFA codes without a real VPN login?

Attackers in the GuidePoint GRIT VPN vishing campaign got passwords and MFA codes by steering employees onto attacker-controlled fake VPN portals under a live helpdesk pretext. The employee typed the username and password on the spoofed Cisco, Fortinet, or Palo Alto-looking page. MFA OTPs were harvested the same way, and push MFA was coached verbally on the call so the victim approved a prompt while still on the phone. That is credential-phase theft at a fake login, not proof the real corporate VPN accepted the attacker first.

Was this the same class of attack as helpdesk TAP or recovery social engineering?

Yes. For the GuidePoint GRIT wave, coached fake VPN login and live coaching of OTP or push material sit in the same social-engineering class as talking support into handing over a recovery secret. In both paths a human is pressured into completing or disclosing a transferable factor. Public reporting on this campaign does not show TAP issuance or helpdesk password resets; it shows SMS fake VPN portals plus OTP harvest and push coaching. A fix that removes transferable login factors exists; the prevention write-up is on the companion post.

Did public reporting show AiTM proxies or stolen session cookies?

No. Public reporting on the GuidePoint GRIT US VPN vishing campaign does not establish adversary-in-the-middle reverse proxies, session-cookie theft, or device-code OAuth flows. What is documented is helpdesk-styled voice pretext, SMS links to fake VPN login pages, and harvest of passwords plus MFA OTPs or coached push approval. Treat unnamed cookie-theft or AiTM claims as unsupported for this wave unless a later primary source adds that detail.

Why did ordinary MFA fail on these workforce VPN paths?

Ordinary MFA failed in the GuidePoint GRIT campaign because the second factor was still something a user could type, read aloud, or approve while a caller walked them through a fake portal. Password plus OTP on an attacker-owned page is satisfied for the attacker the moment the victim complies. Push approval under live voice pressure fails the same way. Closing that phishable VPN login path stops this harvest. Malware after a legitimate login is a harder, separate problem, and public reporting does not show that residual path here.