Okta is investigating reports of a breach after Lapsus$ group posted alleged internal system screenshots; CEO says they could be related to a January incident
Authentication services provider Okta Inc (OKTA.O) is investigating a report of a digital breach, the company said on Tuesday … Source: @toddmckinnon and @toddmckinnon .
Reuters Raphael Satter
Context & Ripple Effects
The allegation prompted an investigation into whether the posted material tied back to a January event. Follow-up coverage identified access to an Okta engineer’s laptop as consistent with the screenshots, shifting the question from authenticity toward customer exposure.
Okta’s later disclosure set a maximum potential impact of 366 customers through contractor Sitel, giving customers and the market a defined, if still consequential, exposure frame.
First-order effects
- Okta must investigate the alleged intrusion and explain whether its January incident accounts for the screenshots, while customers assess whether their environments were among those exposed.
- The company’s public assurance burden rises immediately because the allegations involve internal systems at an authentication provider.
Second-order effects
- Customers potentially tied to Sitel face pressure to review their Okta exposure and seek clearer incident details, while Okta’s contractor-access controls become a focal point of scrutiny.
- The episode raises the competitive value of demonstrable safeguards around contractor and support access for identity-service providers.
Third-order effects
- If identity vendors repeatedly expose customer-facing systems through contractor or support pathways, procurement is likely to place more weight on third-party access governance alongside core authentication features.
- The pattern points toward identity-security resilience being judged not only by platform controls but by the operational controls surrounding vendors and support staff.
The trend: Identity providers are increasingly being evaluated on the security of their extended access ecosystem, not solely on the authentication service they sell.
Related: Okta · Okta confirms attacker accessed engineer laptop · Okta details maximum potential customer impact · Okta probe of third-party vendor breach
Related Coverage
- View article CNN
- Okta investigating claims of customer data breach from Lapsus$ group BleepingComputer · Ax Sharma
- View article Wired
- View article AppleInsider
- View article Protocol
- Microsoft, Okta Investigating Data Theft Claims SecurityWeek · Eduard Kovacs
- Cyber company Okta is latest potential victim of Lapsus$ hackers CyberScoop · Joe Warminsky
- Authentication oufit Okta investigating Lapsus$ breach report The Register · Richard Speed
- Okta confirms January breach after hackers publish screenshots of its internal network TechCrunch · Zack Whittaker
- Authentication Firm Okta Probes Report of Digital Breach Slashdot · Msmash
- Okta Stock Tumbles Amid Digital Breach Investigation As Cybersecurity Risks Mount TheStreet · Martin Baccardax
- Okta Lapsus$ breach: ‘No evidence’ of malicious activity but supply chain attack fears linger Tech Monitor · Matthew Gooding
- Okta Breached By Lapsus$, Exposing Customer Data, Group Claims CRN · Michael Novinson
- Okta security breach may affect Mac and iPhone enterprise setups; vigilance urged 9to5Mac · Ben Lovejoy
- Okta Shares Fall After Hacking Group Lapsus$ Claims Data Breach Bloomberg · Jamie Tarabay
- Okta Investigates Reports of a Digital Breach Wall Street Journal · Ben Otto
- Authentication firm Okta says it has found no evidence of new attack after hackers claim breach CNBC · Arjun Kharpal
- Businesses Brace for Impact After Hackers Claim Okta Has Been Hacked PCMag · Matthew Humphries
- Okta hack puts thousands of businesses on high alert The Verge · Jon Porter
- View article The Hacker News
- View article Security Affairs
- Authentication Giant Okta Breached Through Customer Support VICE · Joseph Cox
- Okta says breach evidence posted by Lapsus$ hackers linked to January ‘security incident’ ZDNet · Charlie Osborne
- Hacker Group Claims Extraordinary Access to User Authentication Firm Okta Gizmodo · Matt Novak
- Hacking group LAPSUS$ leaks Microsoft source code and LG accounts PC Gamer
- View article Bloomberg Law
- Lapsus$ claims to have breached authentication firm Okta cybernews.com · Vilius Petkauskas
- Okta Is Investigating a Digital Breach. The Stock Is Falling Sharply. Barron's Online · Rupert Steiner
- Okta confirms investigation into potential breach The Record · Andrea Peterson
- Okta Investigates Possible Lapsus Breach infosecurity-magazine.com · Phil Muncaster
- LAPSUS$ ransomware group claims Okta breach CSO · Scott Carey
Discussion
-
@toddmckinnon
Todd McKinnon
on x
In late January 2022, Okta detected an attempt to compromise the account of a third party customer support engineer working for one of our subprocessors. The matter was investigated and contained by the subprocessor. (1 of 2)
-
@toddmckinnon
Todd McKinnon
on x
We believe the screenshots shared online are connected to this January event. Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January. (2 of 2)
-
@billdemirkapi
Bill Demirkapi
on x
The LAPSUS$ ransomware group has claimed to breach Okta sharing the following images from internal systems. https://twitter.com/...
-
@_mg_
@_mg_
on x
Oh man, if this it what it looks (Okta got popped)... Blue Team everywhere is gonna be crazy busy. https://twitter.com/...
-
@eastdakota
@eastdakota
on x
We are aware that @Okta may have been compromised. There is no evidence that Cloudflare has been compromised. Okta is merely an identity provider for Cloudflare. Thankfully, we have multiple layers of security beyond Okta, and would never consider them to be a standalone option.
-
@vxunderground
@vxunderground
on x
LAPSUS$ extortion group claims to have breached @Okta. They have released 8 photos as proof. The photos we are sharing has been edited so no sensitive information or user identities are displayed. Image 1 - 4 attached below. https://twitter.com/...
-
@billdemirkapi
Bill Demirkapi
on x
LAPSUS$ edited their message to clarify that they did not breach Okta's databases, but rather targeted Okta customers. https://twitter.com/...
-
@billdemirkapi
Bill Demirkapi
on x
It is possible that LAPSUS$ might have gotten all this access by abusing Okta's own remote control tooling they use to spy on their employees. It would explain things like why the Chrome browser is signed into a user. https://twitter.com/...
-
@eastdakota
@eastdakota
on x
Can anyone who's gotten a satisfactory answer to #Log4J #Log4Shell from @Okta raise their hand? We certainly haven't. #rottenfishstinks
-
@hacks4pancakes
Lesley Carhart
on x
Rational brain says this was a logical supply chain compromise, but Galaxy Brain says the ultimate goal of this intrusion was to scare infosec professionals on Twitter off from implementing MFA.
-
@billdemirkapi
Bill Demirkapi
on x
The screenshots are very worrisome. In the pictures below, LAPSUS$ appears to have gotten access to the @Cloudflare tenant with the ability to reset employee passwords: https://twitter.com/...
-
@eastdakota
@eastdakota
on x
We are resetting the @Okta credentials of any employees who've changed their passwords in the last 4 months, out of abundance of caution. We've confirmed no compromise. Okta is one layer of security. Given they may have an issue we're evaluating alternatives for that layer.
-
@vxunderground
@vxunderground
on x
LAPSUS$ isn't a ransomware group, so stop calling them a ransomware group. Ransomware groups use ransomware, hence the term “ransomware group”. LAPSUS$ doesn't use ransomware. Stop calling LAPSUS$ a ransomware group.
-
@lukolejnik
Lukasz Olejnik
on x
Identity & access management Okta hacked, data stolen and leaked. Access systems. So now, maybe the key question is if company customers may be affected (i.e. easier entry to their systems) with risks of being hacked. https://www.reuters.com/...
-
@razhael
Raphael Satter
on x
Our story: Okta is looking into a reported breach after hackers post screenshots of what they claim is its internal environment. @BillDemirkapi says the images look real. @viss says Okta's customers should be on their toes. https://www.reuters.com/... https://twitter.com/...
-
@_mg_
@_mg_
on x
Yep. LAPSUS is claiming to have been in Okta for 2 months. How many customer networks do you suppose they have been in as a result? What percent haven't detected anything so far? https://twitter.com/... https://twitter.com/...
-
@malwaretechblog
Marcus Hutchins
on x
There's no group that confuses me as much as LAPSUS. They appear to be kids but are claiming responsibility for hacking top tier companies like Nvidia, Microsoft, and Okta. IDK how a group can be that competent and incompetent at the same time. I want it to be a PsyOp so bad.
-
@swiftonsecurity
@swiftonsecurity
on x
Using Okta still better than not having managed identity. You were absolutely fucked before, it just didn't have a bowtie in the newspapers https://twitter.com/...
-
@quinnypig
Corey Quinn
on x
“Okta knew and didn't disclose it for months AWS-style” and “Okta didn't know” are both extremely terrifying.
-
@micheal
Micheal Benedict
on x
Okta should at least want to make an official statement on this topic to allay customer concerns. The legal team is probably on overdrive with liability concerns — DPAs can get gnarly https://twitter.com/...
-
@billdemirkapi
Bill Demirkapi
on x
Another scary note is the date in the VM used in the screenshot consistently appears to be January 21st, 2022. If this date is correct, this would suggest @okta failed to publicly acknowledge any breach for at least two months. https://twitter.com/...
-
@_mg_
@_mg_
on x
LAPSUS looks to be in everything of Okta's. JIRA, Slack, Etc. But some of the screenshots seems to show Super User access capable of modifying/accessing customer accounts. 😬😬 This is gonna be a ride. 🔥
-
@aadhansen
Andreas
on x
Highly embarrassing breach for $okta Their whole company relies on them being a trusted provider for Oauth. How can you outsource your identity needs to a company that can't even secure its own? https://www.reuters.com/...
-
@nixcraft
@nixcraft
on x
Good god. @okta may have been compromised. It is going to be a nightmare if this is true. It appears hackers had access, according to various Tweets, at least since Jan/21. Can you imagine incident response and enterprise security now? https://twitter.com/...
-
@gergelyorosz
Gergely Orosz
on x
The second worst thing to happen to an identity provider is a breach allowing attackers to access customers' data using them. The worst thing is not being aware of such a breach for months. Okta - a cloud identity provider - might have had this worst case happen with them. https:…
-
@quinnypig
Corey Quinn
on x
“I'll just check Twitter real quick before bed” says the Infosec Director at the SaaS company. https://twitter.com/...
-
@swiftonsecurity
@swiftonsecurity
on x
Alright, you selected “Identity Infrastructure compromise!” Now we're party'n! https://twitter.com/...
-
@theregister
@theregister
on x
Authentication providers getting pwned by ransomware gangs is not the zero-trust future we had in mind
-
@viss
@viss
on x
this is is gonna be reeeeeal interesting https://twitter.com/...
-
@_mg_
@_mg_
on x
Based on screenshots, this was an outsourced contractor (working at SYKES) who was working for Okta. Probably a call center employee. Contractors are a common “soft” pathway for most companies.
-
@campuscodi
Catalin Cimpanu
on x
They used ransomware in a few intrusions last year, and have been lumped in that crowd, but the recent incidents did not involve ransomware. https://twitter.com/...
-
@carnage4life
@carnage4life
on x
If Okta was hacked and the hackers spent two months accessing the networks of their customers then this is pretty much the worst case scenario for an enterprise identity provider. It's the enterprise version of LastPass getting hacked. https://twitter.com/...
-
@billdemirkapi
Bill Demirkapi
on x
More screenshots demonstrating access to “superuser”, perhaps Okta's administrative access panel? Other access includes Jira and Slack for Okta. https://twitter.com/...
-
@wbm312
Whitney Merrill
on x
Pour one out for the IR team at @okta tonight.
-
@viss
@viss
on x
i wonder what the cross section is of orgs that have been hit by solarwinds, then verkada, and now okta right in the blueteam oh to be a fly on the wall of the subsequent budget meetings
-
@billdemirkapi
Bill Demirkapi
on x
LAPSUS$ appears to have gained access to some company VPNs given the Cisco AnyConnect icon and the GlobalProtect window in this image. https://twitter.com/...
-
@suhail
@suhail
on x
Jeez. If okta got hacked, it might be a long string of leaks worldwide. Total nightmare scenario.
-
@beaker
@beaker
on x
This 🧵 does not get more comforting the deeper you read. They don't call it single sign-on for nothing...mad feels to all the defenders getting the midnight page-outs https://twitter.com/...
-
@nojonesuk
Nick Jones
on x
#hugops to everyone in the Okta security team this week, it's going to be a long one. For orgs using Okta, the details aren't clear, so I'd be threat hunting for successful auths to services where there's no matching okra session (a la golden SAML). I'd also be looking for... htt…
-
@troyhunt
Troy Hunt
on x
This is a pretty bold claim, very little news on it so far other than Okta is looking into it: https://cnn.com/... https://twitter.com/...
-
@violetblue
Violet Blue®
on x
I want to mention that Okta has *thousands* of clients: https://www.okta.com/... Examining for today's Cybersecurity Roundup, these include Cloudflare, Zoom, FedEx, HP, FCC, T-Mobile, Dignity Health, HackerOne, GrubHub, JetBlue, Trevor Project, GitHub, GoDaddy, Sonos... https://t…
-
@starlingbank
@starlingbank
on x
We're aware of an alleged security breach at Okta. There's no evidence Starling has been compromised. We use Okta for access to some systems, but our app and online banking do not use Okta. As a precaution, we're putting in place planned measures to mitigate potential risks. 1/2
-
@evacide
Eva
on x
So...this is very bad. Pour one out for Okta's security team. https://twitter.com/...