/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Okta's stock closes down 11.57% after the cybersecurity company said a hacker accessed its support system using a stolen credential and viewed client files

- Cybersecurity firm Okta said an unidentified hacker had accessed the company's support system and viewed client files.

CNBC Rohan Goswami

Context & Ripple Effects

The disclosure adds to a recent sequence of Okta security incidents: a 2022 contractor-related breach affected up to 366 customers, followed by a GitHub intrusion involving source code. That history makes a compromise of the customer-support environment more consequential for an identity-security provider, where customer trust is central to the product.

The initial scope did not remain static. Subsequent coverage said files from 134 customers were accessed and that five were later targeted in session-hijacking attacks; later reporting said the breach involved information on all users of the support system, rather than the initially stated 1%.

First-order effects

  • Okta faces an immediate market-confidence hit, reflected in the 11.57% share-price decline, while affected customers must assess what client files exposed through the support system could enable.
  • The incident shifts the support environment from a back-office function to an active security concern, particularly after follow-on session-hijacking attempts against five customers were disclosed.

Second-order effects

  • Enterprise customers and prospects are likely to scrutinize the security of support workflows, credentials, and uploaded diagnostic files alongside the security of Okta’s core service.
  • The widening account of the incident—from a limited initial estimate to information affecting all support-system users—raises the cost of incomplete early breach scoping for vendors and their customers.

Third-order effects

  • If this pattern persists, identity-security providers will be judged not only on authentication defenses but also on the operational systems surrounding them, including support portals and employee access controls.
  • Repeated disclosures can make incident transparency and demonstrable containment a competitive differentiator in identity security, though the longer-term customer impact depends on remediation and whether follow-on abuse continues.

The trend: Identity-security risk is expanding from core login infrastructure to the support and operational systems that hold customer data and can enable downstream account attacks.

Discussion

  • @marceloplima Marcelo P. Lima on x
    $OKTA management is a joke. They completely messed up the sales team integration when they acquired Auth0, then fired the highly-paid executive in charge (Susan St. Ledger). Then, one of their support agents was hacked (May '22) and their crisis management was severely lacking...…
  • @kimzetter Kim Zetter on x
    Worth highlighting that Okta discovered this only because Beyond Trust reported to them that someone was trying to hack BT using a session cookie stolen from Okta - Okta didn't believe BT, and it took them two weeks to confirm that, yes ,they had been breached
  • @gn3mes1s @gn3mes1s on x
    Solid blogpost on the impact of okta support attack. - okta session hijack bypass mfa - admin action using prpxy - admin priv to non admin user
  • @beyondtrust @beyondtrust on x
    BeyondTrust security teams discovered a breach of Okta Support unit impacting multiple organizations after detecting and preventing an identity-centric attack on an in-house Okta account https://beyondtrust.com/... #Okta #IdentitySecurityInsights [image]
  • @kimzetter Kim Zetter on x
    On Oct 13, while Okta was investigating a breach of the company, its chief legal officer Larissa Schwartz ( https://www.okta.com/...) appears to have sold 3,578 of the company's shares, at a market value of $304,237. She still owns a lot of shares, though https://investor.okta.co…
  • @gergelyorosz Gergely Orosz on x
    This is embarrassing for Okta. Both that it's a second breach: and how a customer of theirs detects Okta was breached before Okta does! “In fact, we contacted Okta about the breach of their systems before they had notified us.” Okta has one job: to keep things secure.
  • @kimzetter Kim Zetter on x
    A really bad day for Okta How Cloudflare Mitigated Yet Another Okta Compromise “On Oct 18, we discovered attacks on our system that we were able to trace back to Okta - threat actors were able to leverage an authentication token compromised at Okta...” https://blog.cloudflare.com…
  • @dnlongen David Longenecker on x
    It should come as no surprise that if identities are at the core of modern intrusion attempts, identity providers would be aggressively targeted by threat actors. Okta's support case management system breached to access case files: https://sec.okta.com/...
  • @marcmaiffret Marc Maiffret on x
    Oct 2nd we prevented an attack on an Okta account. Forensics led us to believe that the point of entry was actually due to a compromise within Okta's Support environment. Okta has now confirmed that to be the case, other customers affected. https://www.beyondtrust.com/ ...
  • @rakeshlobster Rakesh Agrawal on x
    A few weeks ago, Okta CEO wouldn't criticize Microsoft's security breach on @reckless podcast because it could happen to Okta, too. The more secure you say something is, the bigger the gantlet you're throwing down.
  • @seanwrightsec Sean Wright on x
    Looks like it took Okta over a week to respond in any meaningful way. That's quite concerning if that was the case!
  • @kimzetter Kim Zetter on x
    Hackers stole access tokens from Okta's support unit. “Okta says the incident affected a ‘very small number’ of customers, however it appears the hackers...had access to Okta's support platform for at least two weeks” https://krebsonsecurity.com/ ...
  • @buccocapital BuccoCapital Guy on x
    At this point who is implementing Okta? Feels like they announce a breach every month
  • @_mg_ @_mg_ on x
    So the front door into tons of companies (Okta) has such bad visibility for their own network that they can't find an intrusion that someone has actively flagged. Sleep well defense teams!
  • @gergelyorosz Gergely Orosz on x
    Absolute savage and deserved. This is Cloudflare saying as indirectly as they can that Okta's practices are not up to par for an organisation that takes security seriously. Much less one that sells security. And they are... right? https://blog.cloudflare.com/ ... [image]