Okta's stock closed down 11.57% on October 20 after the cybersecurity firm said a hacker used a stolen credential to access its support system and client files
- Cybersecurity firm Okta said an unidentified hacker had accessed the company's support system and viewed client files.
CNBCRohan Goswami
Context & Ripple Effects
This disclosure followed an earlier Okta incident in which a contractor-related breach affected up to 366 customers and a separate report of stolen source code from GitHub repositories. The new episode put Okta's customer-support environment—not just its product-development systems—at the center of its security posture.
Subsequent coverage showed that the initially described exposure had a wider customer footprint: files from 134 customers were accessed, and Okta later said information was taken on all users of its support system, revising an earlier narrower characterization of the impact.
First-order effects
Okta faced an immediate market-confidence hit, with its shares closing down 11.57% after the disclosure.
Customers whose support files may have been viewed had to assess what information was exposed and whether it could enable follow-on account or identity attacks.
Second-order effects
The breach raised the stakes for support portals and uploaded diagnostic files as security-sensitive systems; later reporting connected five affected customers to session-hijacking attacks.
If support tooling remains a productive path into identity providers and their customers, security evaluations will increasingly cover vendor support operations, credentials, and uploaded files alongside core production infrastructure.
Repeated incidents can make breach containment and the precision of initial disclosures a competitive trust issue for identity-security vendors, not solely an operational response task.
The trend: Identity-security risk is broadening from the authentication platform itself to the surrounding support and operational systems that hold customer context.
$OKTA management is a joke. They completely messed up the sales team integration when they acquired Auth0, then fired the highly-paid executive in charge (Susan St. Ledger). Then, one of their support agents was hacked (May '22) and their crisis management was severely lacking...…
Worth highlighting that Okta discovered this only because Beyond Trust reported to them that someone was trying to hack BT using a session cookie stolen from Okta - Okta didn't believe BT, and it took them two weeks to confirm that, yes ,they had been breached
BeyondTrust security teams discovered a breach of Okta Support unit impacting multiple organizations after detecting and preventing an identity-centric attack on an in-house Okta account https://beyondtrust.com/... #Okta #IdentitySecurityInsights [image]
On Oct 13, while Okta was investigating a breach of the company, its chief legal officer Larissa Schwartz ( https://www.okta.com/...) appears to have sold 3,578 of the company's shares, at a market value of $304,237. She still owns a lot of shares, though https://investor.okta.co…
This is embarrassing for Okta. Both that it's a second breach: and how a customer of theirs detects Okta was breached before Okta does! “In fact, we contacted Okta about the breach of their systems before they had notified us.” Okta has one job: to keep things secure.
A really bad day for Okta How Cloudflare Mitigated Yet Another Okta Compromise “On Oct 18, we discovered attacks on our system that we were able to trace back to Okta - threat actors were able to leverage an authentication token compromised at Okta...” https://blog.cloudflare.com…
It should come as no surprise that if identities are at the core of modern intrusion attempts, identity providers would be aggressively targeted by threat actors. Okta's support case management system breached to access case files: https://sec.okta.com/...
Oct 2nd we prevented an attack on an Okta account. Forensics led us to believe that the point of entry was actually due to a compromise within Okta's Support environment. Okta has now confirmed that to be the case, other customers affected. https://www.beyondtrust.com/ ...
A few weeks ago, Okta CEO wouldn't criticize Microsoft's security breach on @reckless podcast because it could happen to Okta, too. The more secure you say something is, the bigger the gantlet you're throwing down.
Hackers stole access tokens from Okta's support unit. “Okta says the incident affected a ‘very small number’ of customers, however it appears the hackers...had access to Okta's support platform for at least two weeks” https://krebsonsecurity.com/ ...
So the front door into tons of companies (Okta) has such bad visibility for their own network that they can't find an intrusion that someone has actively flagged. Sleep well defense teams!
Absolute savage and deserved. This is Cloudflare saying as indirectly as they can that Okta's practices are not up to par for an organisation that takes security seriously. Much less one that sells security. And they are... right? https://blog.cloudflare.com/ ... [image]
With the current issues at GitHub, it's a good time to think about monitoring your Okta logs. Are you bringing Okta logs into your SIEM? What detections are in place? https://panther.com/...
Okta compromised... again. Here's how @Cloudflare, even though we were (again) targeted, was able to mitigate the attack. And some best security practice suggestions for @okta and their customers. https://blog.cloudflare.com/ ...