Phishing-proof device-bound MFA would have blocked the credential-phishing path into UC San Diego Health employee email. According to the California Attorney General sample individual notification tied to the 27 July 2021 substitute notice, unauthorized access to workforce mailboxes ran from 2 December 2020 through 8 April 2021, and reporting cites roughly 495,949 individuals potentially exposed. Public reporting does not establish MFA enrollment, any second-factor failure method, AiTM tooling, or how many mailboxes were taken over. Closing a phishable workforce email login stops this account-takeover class. Mailbox reading after a live session exists is a harder, separate problem. For the full multi-month attack-chain timeline, read the companion on legacymfa.sucks.

FAQ

Would phishing-proof MFA have stopped the UC San Diego Health email phishing path?

Yes. Phishing-proof MFA would have stopped the UC San Diego Health employee email phishing path at initial access. MFA 2.0 removes transferable login factors so a stolen or typed password alone cannot open those workforce mailboxes. Public reporting describes phishing-driven unauthorized access to workforce email and does not establish whether MFA was enrolled or how any second factor failed. Device-bound, origin-bound signatures leave nothing useful to type on a fake page or relay in real time. That is prevention of the login, not a claim that MFA was bypassed in this case.

Why can't any MFA reverse UC San Diego Health mailbox exposure after login?

No MFA stops attackers from reading UC San Diego Health mailbox content once authentication has already succeeded and a live session exists. Prevention value sits only upstream, where the phishing path should never have completed sign-in. After that point defenders need session revoke, credential rotation, and mailbox forensics. Closing the phishable login is the prevention claim. Revoke remains hygiene for access that already exists.

How do passkeys compare to MFA 2.0 for this workforce email path?

Passkeys are phishing-resistant at the login ceremony. They harden origin-bound authentication, but enrollment and recovery can still use email OTP, SMS, or other transferable factors unless the deployment forbids that. MFA 2.0 is phishing-proof across the identity lifecycle, so no phishable factor appears at registration, device onboarding, authentication, or decommissioning. For UC San Diego Health, where MFA status is unspecified, full-lifecycle device-bound credentials shrink this workforce email ATO class more tightly than password or OTP login alone. The architecture that binds credentials to hardware is what removes the reusable secret.

What should a healthcare CISO change after UC San Diego Health-style email ATO?

Replace phishable workforce email login factors with phishing-proof device-bound credentials so a phishing campaign cannot finish mailbox sign-in. Pair that with fast session revoke and endpoint hygiene for any residual compromise after a legitimate login. Do not treat user caution or after-the-fact detection as the primary control for this path. Prevention over detection puts the hardware boundary before the inbox, which is where this breach class actually starts.

Does MFA 2.0 stop malware that steals a mailbox session after a real login?

No. MFA 2.0 does not stop malware or an infostealer on a PC that already holds a legitimate UC San Diego Health email session. Fooling a user into completing a phishable login is easy. Planting malware is not. Public reporting on this incident documents phishing-driven account compromise, not endpoint malware as the initial path. Closing the phishable login stops the remote phishing path; residual local token theft needs endpoint controls and revoke.