Leaked Mandiant report: Okta's contractor Sitel first sent a Lapsus$ breach notification to Okta on January 25 and a detailed “Intrusion Timeline” on March 17
Documents shed some light on how Okta and its subprocessor Sitel reacted to a breach, but they don't explain the apparent lack of urgency.
Wired Lily Hay Newman
Context & Ripple Effects
Okta's public response began after Lapsus$ posted alleged screenshots, prompting an investigation into a possible January incident. It then confirmed access to an engineer's laptop and said Sitel's access created a maximum potential impact for 366 customers.
The leaked Mandiant material adds a chronology to that sequence: Sitel notified Okta in January, well before the late-March public disclosures. That timing makes the gap between vendor notice, investigation, and customer understanding the central issue.
First-order effects
- Okta and Sitel face sharper scrutiny over incident handling because the reported January 25 notice and March 17 timeline predate Okta's public confirmation of the contractor-linked access.
- Customers included in Okta's stated maximum potential-impact group gain a clearer basis to question when Okta understood the vendor incident and what exposure information was available.
Second-order effects
- Okta's later finding that the intrusion lasted 25 consecutive minutes and affected two active customers, reported in its completed vendor-breach probe, must be assessed against the earlier notification chronology rather than only the final scope.
- Identity-service customers and their security teams are likely to place greater weight on how quickly a provider converts a contractor's alert into a usable exposure assessment.
Third-order effects
- Third-party access becomes a more consequential governance issue for identity providers: vendor notification and escalation records can shape customer trust as much as the eventual technical scope of an intrusion.
- The episode points toward security accountability extending across the provider-subprocessor chain, with incident-response speed becoming part of how enterprise buyers evaluate identity vendors.
The trend: Identity-security vendors are being judged not only on breach containment, but on the speed and clarity with which contractor incidents are escalated to affected customers.
Related: Okta · Sitel · Okta investigates Lapsus$ breach reports · Okta details maximum potential customer impact · Okta completes third-party vendor breach probe
Related Coverage
- Lapsus$ and SolarWinds hackers both use the same old trick to bypass MFA Ars Technica · Dan Goodin
- Powerful Cyberattack Knocked Out Ukraine's Top Terrestrial Telco for Fifteen Hours Metacurity · Cynthia Brumfield
- Lapsus$ found a spreadsheet of passwords as they breached Okta, documents show TechCrunch · Zack Whittaker
- View article The New Stack
- Okta apologizes for waiting two months to notify customers of Lapsus$ breach The Record · Jonathan Greig
- View article Newslit Daily
- View article Digital Trends
- This is Mandiant's timeline for the Okta Lapsus$ breach, according to a researcher VentureBeat · Kyle Alspach
- New Report on Okta Hack Reveals the Entire Episode LAPSUS$ Attack The Hacker News · Ravie Lakshmanan
- Okta compromised by supplier's security lapses iTnews · Juha Saarinen
- Okta says document ‘appears to be’ part of report on Lapsus$ breach VentureBeat · Kyle Alspach
- Daily Authority: 📁 X Fold coming Android Authority · Tristan Rayner
- Lack of speedy notification was ‘a mistake,’ Okta says CyberScoop · Joe Warminsky
Discussion
-
@billdemirkapi
Bill Demirkapi
on x
New documents for the Okta breach: I have obtained copies of the Mandiant report detailing the embarrassing Sitel/SYKES breach timeline and the methodology of the LAPSUS$ group. 1/N https://twitter.com/... https://twitter.com/...
-
@zackwhittaker
Zack Whittaker
on x
New documents offer the most detailed account so far of how the Lapsus$ group hacked Sitel, including how the hackers accessed a spreadsheet of ‘domain admin’ passwords on Sitel's network at the time they were compromising Okta. https://techcrunch.com/...
-
@zackwhittaker
Zack Whittaker
on x
According to a timeline of the Sitel intrusion compiled by Mandiant (dated March 17), the Lapsus$ hackers accessed a spreadsheet on Sitel's internal network called “DomAdmins-LastPass.xlsx” early on January 21, around the time Okta was compromised. https://techcrunch.com/...
-
@billdemirkapi
Bill Demirkapi
on x
I have been terminated from Zoom for refusing to remove the following tweets. Anyone have recommendations for wrongful termination lawyers based in California? https://twitter.com/...
-
@billdemirkapi
Bill Demirkapi
on x
My questions for Okta: You knew that the machine of one of your customer support members was compromised back in January. Why didn't you investigate it? Having the capability to detect an attack is useless if you aren't willing to respond. 7/N
-
@billdemirkapi
Bill Demirkapi
on x
Good questions to ask include: Who knows how your sub-processors handle their own security? As we saw in this case, Sitel didn't take the security of their environment very seriously. What can an attacker do if one of your sub-processors becomes compromised? 11/N
-
@billdemirkapi
Bill Demirkapi
on x
LAPSUS$ used off-the-shelf tooling from GitHub for the majority of their attacks. After downloading Process Explorer and Process Hacker, LAPSUS$ bypassed the FireEye endpoint agent by simply terminating it! 3/N https://twitter.com/...
-
@ninjaparanoid
@ninjaparanoid
on x
Not surprised by this as a similar thing happened to me when I was in Mandiant. Most companies try to control what their employees post even if it's not related to their organization. I was about to get terminated too, but I decided to delete my tweets. One of the reasons I left.…
-
@lilyhnewman
Lily Hay Newman
on x
just continues to be extremely unclear why Okta and its sub-processor Sitel apparently didn't have a greater sense of urgency about investigating this breach and its implications for their customers https://www.wired.com/...
-
@billdemirkapi
Bill Demirkapi
on x
We can see how LAPSUS$ originally began investigating their compromised host on January 19th, 2022. With little regard for OPSEC, LAPSUS$ searched for a CVE-2021-34484 bypass on their compromised host and downloaded the pre-built version from GitHub. 2/N https://twitter.com/... h…
-
@racheltobac
Rachel Tobac
on x
A reminder that passwords stored *in a password manager* are great... Passwords exported from a password manager into a spreadsheet saved on the network as DomAdmins-LastPass.xlsx...not great at all. https://twitter.com/...
-
@cyb3rops
@cyb3rops
on x
What's the first thing advanced threat groups do after the first successful login on a target system with low privileges? Correct, they use the local browser to run a Bing search for privilege escalation tools on Github. https://twitter.com/... https://twitter.com/...
-
@zackwhittaker
Zack Whittaker
on x
Okta was unable to comment when reached prior to publication. Sitel and Mandiant did not dispute the contents of the reports but declined to comment when spokespeople were reached.
-
@zackwhittaker
Zack Whittaker
on x
“It is also unclear why [Sitel and Okta] do not seem to have mounted more expansive and urgent responses while Mandiant's investigation was ongoing.” https://wired.com/... https://twitter.com/...
-
@gentilkiwi
@gentilkiwi
on x
Your best security measure is to block Bing search. Or I missed something? https://twitter.com/...
-
@evanderburg
Eric Vanderburg
on x
New Lapsus$ Hack Documents Make Okta's Response Look More Bizarre https://securitytc.com/SMXNtC https://twitter.com/...
-
@kostastsale
Kostas
on x
I don't even know where to start... Fireeye endpoint terminated using Process Explorer, Bing search looking for Mimikatz, the two month response time? Oh boy, so many things to unravel here 😂 Very nice thread and juicy info 👇 https://twitter.com/...
-
@quentynblog
Quentyn Taylor
on x
I am amazed that the mandiant report into the okta / sitel hack seems to have leaked. Unless the leak was deliberate, I consider this to be more serious than the original hack.... It shows a breakdown of any kind of confidentiality, though to be fair its an interesting report
-
@billdemirkapi
Bill Demirkapi
on x
With the endpoint agent disabled, LAPSUS$ simply downloaded the official version of Mimikatz (a popular credential dumping utility) directly from its repository. 4/N https://twitter.com/...
-
@_mg_
@_mg_
on x
This shows a lot of layers of security breakdown happening here. This is bigger than Okta. I promise that a lot of these fails are easily observed at many companies. Take notes, learn, improve. https://twitter.com/...
-
@troyhunt
Troy Hunt
on x
Looks like some eating of humble pie, responses to Okta over their handling of this have not been kind: https://twitter.com/...
-
@vickerysec
Chris Vickery
on x
Sign of a super-sophisticated Advanced Persistent Threat actor: “Bing search for Mimikatz” (for the non-tech-savvy, my words above are dripping with sarcasm) https://twitter.com/... https://twitter.com/...
-
@_rastamouse
@_rastamouse
on x
I can't even.... https://twitter.com/...
-
@viss
@viss
on x
they broke in, then used the victim network (okta) to bing search for privesc tools. WOW. https://twitter.com/...
-
@gossithedog
Kevin Beaumont
on x
Microsoft got me to remove tweets about Mandiant (praising them) and about Exchange (during ProxyLogon). Gotta control the message. https://twitter.com/...
-
@mjg59
Matthew Garrett
on x
Looking at https://twitter.com/..., it's interesting to think about the degree to which modern security controls would have helped mitigate this attack. It's also important to note that what many people think of as ZTA would have been no help at all.
-
@racheltobac
Rachel Tobac
on x
Many reasons why a person may have made this mistake — maybe they didn't understand that a group password manager would have allowed them to share the relevant passwords with their colleagues safely, maybe they didn't get that downloading & storing pws this way is not secure...
-
@viss
@viss
on x
everyone on a redteam is walking on eggshells, doing insane opsec stuff seen in practically-only-nation-state- level campaigns, but the big hacks? they break in with stolen creds, openly search for tools on the victim network, and download commonly available tools.
-
@ravirockks
Ravi Nayyar
on x
‘Sitel and Mandiant did not dispute the contents of the reports but declined to comment’. Well, well, well.
-
@chvancooten
Cas van Cooten
on x
Not sure what's more shocking, the “DomAdmins-LastPass.xlsx” file or that the attackers used BING to look up privilege escalation tools on a compromised machine 😅 https://twitter.com/...
-
@corg_e
@corg_e
on x
“Bing search for privesc tools” 🤡😂 https://twitter.com/...
-
@alexstamos
Alex Stamos
on x
Congrats to the Microsoft Bing team for being the favorite search engine of the LAPSUS$ kids looking for mimikatz. https://twitter.com/...