No push to fatigue. No code to relay. No helpdesk agent to talk around. In each of these breaches the attacker typed a password into a workforce portal that never asked for anything else.
Password-only portal breaches happen when one VPN profile, remote-access gateway, support account, webmail path, or test tenant still accepts a password alone. Public testimony, regulator findings, and vendor statements document that at Colonial Pipeline, Change Healthcare, PowerSchool, Microsoft, and Healthplex. The organizations had MFA elsewhere. The attacker found the path where they did not.
This rolling hub tracks that coverage gap across sectors. Each incident has its own detailed write-up: Colonial Pipeline's legacy VPN, Change Healthcare's Citrix portal, PowerSchool's PowerSource support login, Microsoft's Midnight Blizzard password spray, and Healthplex's Outlook Web Access.
The door that still accepts only a password
Colonial Pipeline is the cleanest example. Mandiant's Charles Carmakal told the House Homeland Security Committee that the earliest evidence of compromise was 29 April 2021, when the attacker logged into a VPN appliance using a legacy VPN profile and an employee's username and password. That profile did not require a one-time passcode. Colonial has since disabled it. The ransomware that led Colonial to halt pipeline operations came later, but the way in was a password and nothing more.
Change Healthcare followed the same shape at larger scale. UnitedHealth Group CEO Andrew Witty's written testimony, reported by BleepingComputer, says criminals used compromised credentials on 12 February 2024 to access a Citrix portal used for remote desktop access. The portal did not have multi-factor authentication. The attackers moved laterally, exfiltrated data, and deployed ALPHV/BlackCat ransomware nine days later, disrupting payment processing, prescription writing, and insurance claims.
PowerSchool's breach ran through a support path. A PowerSchool spokesperson confirmed to TechCrunch that the subcontractor account used to breach its PowerSource customer support portal was not protected with MFA. PowerSchool said it discovered the breach on 28 December, and the stolen data included sensitive personal information on students and teachers.
Microsoft's case started in a corner of its own estate. Microsoft Threat Intelligence wrote that Midnight Blizzard used a password spray to compromise a legacy, non-production test tenant account that did not have MFA enabled. From there the actor abused a legacy test OAuth application with elevated access, created malicious OAuth applications, and granted itself the Exchange full_access_as_app role to reach corporate mailboxes.
Healthplex shows how a migration can open the door. New York's financial regulator found in its consent order that after an Office 365 move, MFA was not enabled for Outlook Web Access. In November 2021 a phishing email invited an employee to enter business email credentials to receive a fax, and they did. The attacker then accessed the mailbox without having to bypass any MFA controls.
| Login path | What happened here | Why it failed |
|---|---|---|
| Colonial legacy VPN profile | Employee password used on 29 April 2021 | Profile required no one-time passcode |
| Change Healthcare Citrix portal | Compromised credentials used 12 February 2024 | Portal had no MFA |
| PowerSchool support portal | Subcontractor account used | Account not protected with MFA |
| Microsoft test tenant | Password spray succeeded | MFA not enabled on that account |
| Healthplex Outlook Web Access | Phished password used in a browser | MFA not enabled after migration |
What MFA on other systems did not fix
None of these organizations were without MFA. PowerSchool told TechCrunch it uses single sign-on and MFA for employees and contractors. Microsoft wrote that if the same team deployed that legacy tenant today, mandatory policy would ensure MFA was enabled. Healthplex had MFA before migrating its email. The breached account sat outside each rule anyway.
That is why coverage dashboards mislead. A legacy VPN profile, a non-production tenant, a subcontractor maintenance login, or a webmail path left behind by a migration rarely shows up in an enrollment count. Microsoft notes that Midnight Blizzard limited its spray to a small number of accounts with few attempts to avoid detection, which is exactly how forgotten exceptions get found. Public reporting does not establish how long any of these paths had been exposed before the attacker used them.
If you want to skip the attack details and go straight to what can stop this, read the related article on mfa2point0.com: Phishing-proof MFA closes password-only portals
FAQ
How did attackers get into Change Healthcare's Citrix portal?
Attackers got into Change Healthcare's Citrix portal on 12 February 2024 using compromised credentials, according to UnitedHealth Group CEO Andrew Witty's written testimony. The portal did not have multi-factor authentication, so the password alone was enough. Ransomware was deployed nine days later.
Did attackers bypass MFA at Colonial Pipeline, Change Healthcare, or PowerSchool?
Attackers did not bypass MFA at Colonial Pipeline, Change Healthcare, or PowerSchool, because the breached path did not require it. Colonial's legacy VPN profile needed no one-time passcode, Change Healthcare's Citrix portal had no MFA, and PowerSchool confirmed the subcontractor support account was not protected with MFA.
How did a Microsoft test tenant without MFA lead to corporate email theft?
Microsoft's Midnight Blizzard breach began when a password spray compromised a legacy test tenant account without MFA. The actor then abused a legacy test OAuth application with elevated access and granted malicious applications full access to Exchange Online mailboxes, which reached corporate email.
Why did MFA elsewhere not protect PowerSchool's support portal?
PowerSchool's support portal breach shows that MFA on other systems does not protect an account left outside policy. PowerSchool said it uses MFA for employees and contractors, yet the subcontractor account used against the PowerSource customer support portal was not protected with MFA.
Updates
2025-01-17: Named victim reporting
PowerSchool confirmed to TechCrunch that the subcontractor account used to breach its customer support portal was not protected with multi-factor authentication.
Source: TechCrunch, Malware stole internal PowerSchool passwords
2024-02-12: Named victim testimony
UnitedHealth Group's CEO testified in writing that compromised credentials opened a Change Healthcare Citrix remote access portal that did not have multi-factor authentication.
Source: BleepingComputer, Change Healthcare hacked using stolen Citrix account with no MFA
2024-01-25: Vendor disclosure
Microsoft Threat Intelligence said Midnight Blizzard's password spray compromised a legacy non-production test tenant account that did not have MFA enabled.
Source: Microsoft Security Blog, Midnight Blizzard guidance for responders
2021-11-24: Regulator finding
NYDFS found that a phished Healthplex employee's mailbox was reached through Outlook Web Access without bypassing any MFA controls, because MFA was not enabled there.
Source: NYDFS, Healthplex consent order
2021-05-07: Named victim testimony
Mandiant testified that Colonial Pipeline's earliest compromise evidence was a VPN login with a legacy profile and an employee's password that required no one-time passcode.
Source: House Homeland Security Committee, Carmakal prepared statement