/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Okta is investigating reports of a breach after Lapsus$ group posted alleged internal system screenshots; CEO says they could be related to a January incident

Authentication services provider Okta Inc (OKTA.O) is investigating a report of a digital breach, the company said on Tuesday … Source: @toddmckinnon and @toddmckinnon .

Reuters Raphael Satter

Context & Ripple Effects

The allegation prompted an investigation into whether the posted material tied back to a January event. Follow-up coverage identified access to an Okta engineer’s laptop as consistent with the screenshots, shifting the question from authenticity toward customer exposure.

Okta’s later disclosure set a maximum potential impact of 366 customers through contractor Sitel, giving customers and the market a defined, if still consequential, exposure frame.

First-order effects

  • Okta must investigate the alleged intrusion and explain whether its January incident accounts for the screenshots, while customers assess whether their environments were among those exposed.
  • The company’s public assurance burden rises immediately because the allegations involve internal systems at an authentication provider.

Second-order effects

  • Customers potentially tied to Sitel face pressure to review their Okta exposure and seek clearer incident details, while Okta’s contractor-access controls become a focal point of scrutiny.
  • The episode raises the competitive value of demonstrable safeguards around contractor and support access for identity-service providers.

Third-order effects

  • If identity vendors repeatedly expose customer-facing systems through contractor or support pathways, procurement is likely to place more weight on third-party access governance alongside core authentication features.
  • The pattern points toward identity-security resilience being judged not only by platform controls but by the operational controls surrounding vendors and support staff.

The trend: Identity providers are increasingly being evaluated on the security of their extended access ecosystem, not solely on the authentication service they sell.

Discussion

  • @toddmckinnon Todd McKinnon on x
    In late January 2022, Okta detected an attempt to compromise the account of a third party customer support engineer working for one of our subprocessors. The matter was investigated and contained by the subprocessor. (1 of 2)
  • @toddmckinnon Todd McKinnon on x
    We believe the screenshots shared online are connected to this January event. Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January. (2 of 2)
  • @billdemirkapi Bill Demirkapi on x
    The LAPSUS$ ransomware group has claimed to breach Okta sharing the following images from internal systems. https://twitter.com/...
  • @_mg_ @_mg_ on x
    Oh man, if this it what it looks (Okta got popped)... Blue Team everywhere is gonna be crazy busy. https://twitter.com/...
  • @eastdakota @eastdakota on x
    We are aware that @Okta may have been compromised. There is no evidence that Cloudflare has been compromised. Okta is merely an identity provider for Cloudflare. Thankfully, we have multiple layers of security beyond Okta, and would never consider them to be a standalone option.
  • @vxunderground @vxunderground on x
    LAPSUS$ extortion group claims to have breached @Okta. They have released 8 photos as proof. The photos we are sharing has been edited so no sensitive information or user identities are displayed. Image 1 - 4 attached below. https://twitter.com/...
  • @billdemirkapi Bill Demirkapi on x
    LAPSUS$ edited their message to clarify that they did not breach Okta's databases, but rather targeted Okta customers. https://twitter.com/...
  • @billdemirkapi Bill Demirkapi on x
    It is possible that LAPSUS$ might have gotten all this access by abusing Okta's own remote control tooling they use to spy on their employees. It would explain things like why the Chrome browser is signed into a user. https://twitter.com/...
  • @eastdakota @eastdakota on x
    Can anyone who's gotten a satisfactory answer to #Log4J #Log4Shell from @Okta raise their hand? We certainly haven't. #rottenfishstinks
  • @hacks4pancakes Lesley Carhart on x
    Rational brain says this was a logical supply chain compromise, but Galaxy Brain says the ultimate goal of this intrusion was to scare infosec professionals on Twitter off from implementing MFA.
  • @billdemirkapi Bill Demirkapi on x
    The screenshots are very worrisome. In the pictures below, LAPSUS$ appears to have gotten access to the @Cloudflare tenant with the ability to reset employee passwords: https://twitter.com/...
  • @eastdakota @eastdakota on x
    We are resetting the @Okta credentials of any employees who've changed their passwords in the last 4 months, out of abundance of caution. We've confirmed no compromise. Okta is one layer of security. Given they may have an issue we're evaluating alternatives for that layer.
  • @vxunderground @vxunderground on x
    LAPSUS$ isn't a ransomware group, so stop calling them a ransomware group. Ransomware groups use ransomware, hence the term “ransomware group”. LAPSUS$ doesn't use ransomware. Stop calling LAPSUS$ a ransomware group.
  • @lukolejnik Lukasz Olejnik on x
    Identity & access management Okta hacked, data stolen and leaked. Access systems. So now, maybe the key question is if company customers may be affected (i.e. easier entry to their systems) with risks of being hacked. https://www.reuters.com/...
  • @razhael Raphael Satter on x
    Our story: Okta is looking into a reported breach after hackers post screenshots of what they claim is its internal environment. @BillDemirkapi says the images look real. @viss says Okta's customers should be on their toes. https://www.reuters.com/... https://twitter.com/...
  • @_mg_ @_mg_ on x
    Yep. LAPSUS is claiming to have been in Okta for 2 months. How many customer networks do you suppose they have been in as a result? What percent haven't detected anything so far? https://twitter.com/... https://twitter.com/...
  • @malwaretechblog Marcus Hutchins on x
    There's no group that confuses me as much as LAPSUS. They appear to be kids but are claiming responsibility for hacking top tier companies like Nvidia, Microsoft, and Okta. IDK how a group can be that competent and incompetent at the same time. I want it to be a PsyOp so bad.
  • @swiftonsecurity @swiftonsecurity on x
    Using Okta still better than not having managed identity. You were absolutely fucked before, it just didn't have a bowtie in the newspapers https://twitter.com/...
  • @quinnypig Corey Quinn on x
    “Okta knew and didn't disclose it for months AWS-style” and “Okta didn't know” are both extremely terrifying.
  • @micheal Micheal Benedict on x
    Okta should at least want to make an official statement on this topic to allay customer concerns. The legal team is probably on overdrive with liability concerns — DPAs can get gnarly https://twitter.com/...
  • @billdemirkapi Bill Demirkapi on x
    Another scary note is the date in the VM used in the screenshot consistently appears to be January 21st, 2022. If this date is correct, this would suggest @okta failed to publicly acknowledge any breach for at least two months. https://twitter.com/...
  • @_mg_ @_mg_ on x
    LAPSUS looks to be in everything of Okta's. JIRA, Slack, Etc. But some of the screenshots seems to show Super User access capable of modifying/accessing customer accounts. 😬😬 This is gonna be a ride. 🔥
  • @aadhansen Andreas on x
    Highly embarrassing breach for $okta Their whole company relies on them being a trusted provider for Oauth. How can you outsource your identity needs to a company that can't even secure its own? https://www.reuters.com/...
  • @nixcraft @nixcraft on x
    Good god. @okta may have been compromised. It is going to be a nightmare if this is true. It appears hackers had access, according to various Tweets, at least since Jan/21. Can you imagine incident response and enterprise security now? https://twitter.com/...
  • @gergelyorosz Gergely Orosz on x
    The second worst thing to happen to an identity provider is a breach allowing attackers to access customers' data using them. The worst thing is not being aware of such a breach for months. Okta - a cloud identity provider - might have had this worst case happen with them. https:…
  • @quinnypig Corey Quinn on x
    “I'll just check Twitter real quick before bed” says the Infosec Director at the SaaS company. https://twitter.com/...
  • @swiftonsecurity @swiftonsecurity on x
    Alright, you selected “Identity Infrastructure compromise!” Now we're party'n! https://twitter.com/...
  • @theregister @theregister on x
    Authentication providers getting pwned by ransomware gangs is not the zero-trust future we had in mind
  • @viss @viss on x
    this is is gonna be reeeeeal interesting https://twitter.com/...
  • @_mg_ @_mg_ on x
    Based on screenshots, this was an outsourced contractor (working at SYKES) who was working for Okta. Probably a call center employee. Contractors are a common “soft” pathway for most companies.
  • @campuscodi Catalin Cimpanu on x
    They used ransomware in a few intrusions last year, and have been lumped in that crowd, but the recent incidents did not involve ransomware. https://twitter.com/...
  • @carnage4life @carnage4life on x
    If Okta was hacked and the hackers spent two months accessing the networks of their customers then this is pretty much the worst case scenario for an enterprise identity provider. It's the enterprise version of LastPass getting hacked. https://twitter.com/...
  • @billdemirkapi Bill Demirkapi on x
    More screenshots demonstrating access to “superuser”, perhaps Okta's administrative access panel? Other access includes Jira and Slack for Okta. https://twitter.com/...
  • @wbm312 Whitney Merrill on x
    Pour one out for the IR team at @okta tonight.
  • @viss @viss on x
    i wonder what the cross section is of orgs that have been hit by solarwinds, then verkada, and now okta right in the blueteam oh to be a fly on the wall of the subsequent budget meetings
  • @billdemirkapi Bill Demirkapi on x
    LAPSUS$ appears to have gained access to some company VPNs given the Cisco AnyConnect icon and the GlobalProtect window in this image. https://twitter.com/...
  • @suhail @suhail on x
    Jeez. If okta got hacked, it might be a long string of leaks worldwide. Total nightmare scenario.
  • @beaker @beaker on x
    This 🧵 does not get more comforting the deeper you read. They don't call it single sign-on for nothing...mad feels to all the defenders getting the midnight page-outs https://twitter.com/...
  • @nojonesuk Nick Jones on x
    #hugops to everyone in the Okta security team this week, it's going to be a long one. For orgs using Okta, the details aren't clear, so I'd be threat hunting for successful auths to services where there's no matching okra session (a la golden SAML). I'd also be looking for... htt…
  • @troyhunt Troy Hunt on x
    This is a pretty bold claim, very little news on it so far other than Okta is looking into it: https://cnn.com/... https://twitter.com/...
  • @violetblue Violet Blue® on x
    I want to mention that Okta has *thousands* of clients: https://www.okta.com/... Examining for today's Cybersecurity Roundup, these include Cloudflare, Zoom, FedEx, HP, FCC, T-Mobile, Dignity Health, HackerOne, GrubHub, JetBlue, Trevor Project, GitHub, GoDaddy, Sonos... https://t…
  • @starlingbank @starlingbank on x
    We're aware of an alleged security breach at Okta. There's no evidence Starling has been compromised. We use Okta for access to some systems, but our app and online banking do not use Okta. As a precaution, we're putting in place planned measures to mitigate potential risks. 1/2
  • @evacide Eva on x
    So...this is very bad. Pour one out for Okta's security team. https://twitter.com/...