ScamSplain

Corporate 'Reset Your VPN / MFA' IT Phish

A fake IT help desk tells employees to 'reset' their VPN or MFA through a link or by approving a prompt, capturing corporate credentials and bypassing multi-factor.

Think a message like this reached you? You can check it right now.

What this scam is

Employees receive a message or call from 'IT' saying their VPN, password, or MFA must be reset or re-verified due to a security update or expiry. The link is a phishing page (sometimes a real-time reverse proxy) that captures the login and MFA code, or the caller 'MFA-fatigues' the employee into approving a push prompt — giving attackers access to corporate systems. Real IT changes are coordinated through known channels; verifying with your help desk and never approving unexpected MFA prompts are the defenses.

What it usually looks like

  • An 'IT' message/call to reset VPN, password, or MFA.
  • A link to a login page or repeated MFA push prompts.
  • Urgency about a security update or expiry.
  • A caller pressuring you to 'just approve it.'

Common warning signs

  • Reset links to non-official sites.
  • Unexpected, repeated MFA approval prompts.
  • IT contacting you first with urgency.
  • Requests for your password or MFA code.

Example wording scammers use

IT Security: Your VPN access expires today. Re-verify your credentials here to avoid lockout: it-portal-reset.net
(Call) 'We're pushing an MFA prompt to fix your account — please approve it.'

These are illustrative examples written by ScamSplain, not real messages.

What the scammers want

  • Your corporate login and MFA code/approval.
  • Access to VPN and internal systems.
  • To bypass multi-factor via fatigue or proxy.

What to do

  • Verify any IT request through your official help desk before acting.
  • Never approve an MFA prompt you didn't initiate; report it.
  • Use phishing-resistant MFA (security keys/number matching).
  • Report the message to security.

What to do if you already responded

  • Tell IT/security immediately; change credentials and revoke sessions/tokens.
  • Re-enroll MFA and check for new rules/access.
  • Report internally and at reportfraud.ftc.gov.

Related scams