Seyfarth Shaw’s Service Desk MFA phone-number swap is a workforce recovery failure, not a clever bypass of a normal login form. According to the Maryland Attorney General breach notice, an actor impersonated an employee, staff replaced the registered MFA phone number, and the actor then reached ADP payroll and diverted direct deposit. Public reporting frames unauthorized access around 20-21 September 2024, discovery of paycheck redirects around 3 November 2024, and impact limited to a single employee payroll account. Phishing-proof MFA 2.0 stops this path by removing the transferable phone factor helpdesk can re-point. For the full attack-chain write-up, read the companion on legacymfa.sucks.

FAQ

Would phishing-proof MFA 2.0 have stopped the Seyfarth Shaw helpdesk phone swap?

Yes. Phishing-proof MFA 2.0 would have stopped the Seyfarth Shaw path at Service Desk re-enrollment. The documented failure was helpdesk social engineering that replaced a registered MFA phone number, which is a transferable factor. Device-bound credentials have no SMS or phone number for staff to re-point after a verbal impersonation. Enrolment that requires an already-enrolled device, rather than a phishable recovery secret, closes that surface. MFA 2.0 does not reverse a paycheck diversion after the attacker already held a usable factor and completed ADP changes. It removes the helpdesk step that made that access possible.

Why does phone-based MFA re-enrollment fail against helpdesk social engineering?

Phone-based MFA re-enrollment fails against helpdesk social engineering because the second factor is a number staff can rewrite. At Seyfarth Shaw, Service Desk modified MFA by replacing the registered phone number after an actor impersonated an employee. Once the factor pointed at the attacker, later sign-in and payroll changes could look like legitimate employee authentication with MFA satisfied. Public reporting does not establish the exact verification steps Service Desk used. The technology problem is clear either way: a swappable phone factor is a credential the helpdesk can hand over under coaching.

Are passkeys enough if helpdesk can still re-enroll devices?

No. Passkeys are phishing-resistant at the login ceremony, but they do not automatically lock enrollment and recovery. If helpdesk can still prove identity with a phone call and then register a new authenticator, an impersonator can enroll their own device and later produce signatures that look legitimate. MFA 2.0 is phishing-proof across the identity lifecycle, including registration, device onboarding, and recovery, so there is no TAP, SMS code, email code, or phone-number swap for IT to complete on a coached call. That full-lifecycle gap is why resistant login alone would not have been a complete answer to Seyfarth Shaw’s Service Desk path.

What still matters after a completed ADP diversion?

After a completed ADP diversion, no login MFA undoes money already redirected. For Seyfarth Shaw, public reporting frames paycheck redirects discovered around 3 November 2024 and impact limited to a single employee payroll account. Public reporting does not establish a named threat actor, ransom, or broader account compromise. Closing the phishable helpdesk re-enrollment path is the prevention claim. Payroll monitoring, rapid deposit-change alerts, and account recovery remain hygiene once someone already authenticated as the employee. The same recovery class showed up later in Marks & Spencer helpdesk password-reset social engineering, where a transferable secret again sat behind the helpdesk desk.

How should workforce helpdesk identity proofing change after Seyfarth?

Workforce helpdesk identity proofing should stop treating a phone call plus a swappable MFA number as high assurance. Seyfarth Shaw shows that verbal employee impersonation plus phone-factor rewrite is enough to open payroll when recovery still issues transferable secrets. Prefer prevention-focused device-bound authentication where adding or replacing a factor requires an already-enrolled device, not a code staff can read out or a number staff can edit. That design makes coached recovery the wrong origin for a new credential, the same way a coached fake login page has nothing useful to type.