Corporate 'Reset Your VPN / MFA' IT Phish
A fake IT help desk tells employees to 'reset' their VPN or MFA through a link or by approving a prompt, capturing corporate credentials and bypassing multi-factor.
Think a message like this reached you? You can check it right now.
What this scam is
Employees receive a message or call from 'IT' saying their VPN, password, or MFA must be reset or re-verified due to a security update or expiry. The link is a phishing page (sometimes a real-time reverse proxy) that captures the login and MFA code, or the caller 'MFA-fatigues' the employee into approving a push prompt — giving attackers access to corporate systems. Real IT changes are coordinated through known channels; verifying with your help desk and never approving unexpected MFA prompts are the defenses.
What it usually looks like
- An 'IT' message/call to reset VPN, password, or MFA.
- A link to a login page or repeated MFA push prompts.
- Urgency about a security update or expiry.
- A caller pressuring you to 'just approve it.'
Common warning signs
- Reset links to non-official sites.
- Unexpected, repeated MFA approval prompts.
- IT contacting you first with urgency.
- Requests for your password or MFA code.
Example wording scammers use
“IT Security: Your VPN access expires today. Re-verify your credentials here to avoid lockout: it-portal-reset.net”
“(Call) 'We're pushing an MFA prompt to fix your account — please approve it.'”
These are illustrative examples written by ScamSplain, not real messages.
What the scammers want
- Your corporate login and MFA code/approval.
- Access to VPN and internal systems.
- To bypass multi-factor via fatigue or proxy.
What to do
- Verify any IT request through your official help desk before acting.
- Never approve an MFA prompt you didn't initiate; report it.
- Use phishing-resistant MFA (security keys/number matching).
- Report the message to security.
What to do if you already responded
- Tell IT/security immediately; change credentials and revoke sessions/tokens.
- Re-enroll MFA and check for new rules/access.
- Report internally and at reportfraud.ftc.gov.