According to Simmons University’s notice reflected in the Massachusetts AG sample filing associated with 13 February 2025, an employee clicked a phishing link framed as a health advisory, entered login credentials, and approved a fraudulent MFA request. Attackers then accessed that employee’s Simmons Workday account. Public reporting does not establish a victim record count, a named threat actor, or a post-login token-theft path.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
How did attackers access the Simmons Workday account?
The attackers accessed a Simmons University employee’s Workday account after that employee clicked a phishing link framed as a health advisory, entered login credentials, and approved a fraudulent MFA request. According to the Massachusetts AG sample notice for Simmons University, those credential and MFA steps came before the Workday access. Public reporting does not name every hop after sign-in.
Did MFA stop the Simmons University phishing path?
No. MFA did not stop the Simmons University incident as the notice describes it. The employee still approved a fraudulent MFA request after submitting credentials on the phishing path, and attackers still reached Workday as that employee. Public reporting does not name the exact MFA method in use. Whatever it was, it was a factor a person could approve under a lure.
What data was exposed after the Simmons Workday takeover?
Public reporting does not establish a specific affected record count for the Simmons University Workday incident. The university’s notice frames payroll and HR data exposure risk from attackers using the employee’s Workday account. Exact data categories beyond that risk framing are not locked down in the available notice summary.
Was this AiTM phishing or session-cookie theft at Simmons?
Public reporting does not establish that the Simmons University attack used an AiTM reverse proxy, device-code phishing, or post-login session-cookie theft. The documented path is a health-advisory phishing link, credential entry, a fraudulent MFA approval, and Workday access as the employee.
Why is “tell staff to be careful” a weak answer here?
“Be careful” did not close the Simmons University path, because the login still accepted phishable secrets and an MFA step a human can approve for someone else. Closing that workforce login class is the durable fix. The prevention write-up lives on the companion article, not in this post.