Okta's stock closes down 11.57% after the cybersecurity company said a hacker accessed its support system using a stolen credential and viewed client files
- Cybersecurity firm Okta said an unidentified hacker had accessed the company's support system and viewed client files.
CNBCRohan Goswami
Context & Ripple Effects
The disclosure adds to a recent sequence of Okta security incidents: a 2022 contractor-related breach affected up to 366 customers, followed by a GitHub intrusion involving source code. That history makes a compromise of the customer-support environment more consequential for an identity-security provider, where customer trust is central to the product.
The initial scope did not remain static. Subsequent coverage said files from 134 customers were accessed and that five were later targeted in session-hijacking attacks; later reporting said the breach involved information on all users of the support system, rather than the initially stated 1%.
First-order effects
Okta faces an immediate market-confidence hit, reflected in the 11.57% share-price decline, while affected customers must assess what client files exposed through the support system could enable.
Enterprise customers and prospects are likely to scrutinize the security of support workflows, credentials, and uploaded diagnostic files alongside the security of Okta’s core service.
The widening account of the incident—from a limited initial estimate to information affecting all support-system users—raises the cost of incomplete early breach scoping for vendors and their customers.
Third-order effects
If this pattern persists, identity-security providers will be judged not only on authentication defenses but also on the operational systems surrounding them, including support portals and employee access controls.
Repeated disclosures can make incident transparency and demonstrable containment a competitive differentiator in identity security, though the longer-term customer impact depends on remediation and whether follow-on abuse continues.
The trend: Identity-security risk is expanding from core login infrastructure to the support and operational systems that hold customer data and can enable downstream account attacks.
$OKTA management is a joke. They completely messed up the sales team integration when they acquired Auth0, then fired the highly-paid executive in charge (Susan St. Ledger). Then, one of their support agents was hacked (May '22) and their crisis management was severely lacking...…
Worth highlighting that Okta discovered this only because Beyond Trust reported to them that someone was trying to hack BT using a session cookie stolen from Okta - Okta didn't believe BT, and it took them two weeks to confirm that, yes ,they had been breached
BeyondTrust security teams discovered a breach of Okta Support unit impacting multiple organizations after detecting and preventing an identity-centric attack on an in-house Okta account https://beyondtrust.com/... #Okta #IdentitySecurityInsights [image]
On Oct 13, while Okta was investigating a breach of the company, its chief legal officer Larissa Schwartz ( https://www.okta.com/...) appears to have sold 3,578 of the company's shares, at a market value of $304,237. She still owns a lot of shares, though https://investor.okta.co…
This is embarrassing for Okta. Both that it's a second breach: and how a customer of theirs detects Okta was breached before Okta does! “In fact, we contacted Okta about the breach of their systems before they had notified us.” Okta has one job: to keep things secure.
A really bad day for Okta How Cloudflare Mitigated Yet Another Okta Compromise “On Oct 18, we discovered attacks on our system that we were able to trace back to Okta - threat actors were able to leverage an authentication token compromised at Okta...” https://blog.cloudflare.com…
It should come as no surprise that if identities are at the core of modern intrusion attempts, identity providers would be aggressively targeted by threat actors. Okta's support case management system breached to access case files: https://sec.okta.com/...
Oct 2nd we prevented an attack on an Okta account. Forensics led us to believe that the point of entry was actually due to a compromise within Okta's Support environment. Okta has now confirmed that to be the case, other customers affected. https://www.beyondtrust.com/ ...
A few weeks ago, Okta CEO wouldn't criticize Microsoft's security breach on @reckless podcast because it could happen to Okta, too. The more secure you say something is, the bigger the gantlet you're throwing down.
Hackers stole access tokens from Okta's support unit. “Okta says the incident affected a ‘very small number’ of customers, however it appears the hackers...had access to Okta's support platform for at least two weeks” https://krebsonsecurity.com/ ...
So the front door into tons of companies (Okta) has such bad visibility for their own network that they can't find an intrusion that someone has actively flagged. Sleep well defense teams!
Absolute savage and deserved. This is Cloudflare saying as indirectly as they can that Okta's practices are not up to par for an organisation that takes security seriously. Much less one that sells security. And they are... right? https://blog.cloudflare.com/ ... [image]