/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Leaked Mandiant report: Okta's contractor Sitel first sent a Lapsus$ breach notification to Okta on January 25 and a detailed “Intrusion Timeline” on March 17

Documents shed some light on how Okta and its subprocessor Sitel reacted to a breach, but they don't explain the apparent lack of urgency.

Wired Lily Hay Newman

Context & Ripple Effects

Okta's public response began after Lapsus$ posted alleged screenshots, prompting an investigation into a possible January incident. It then confirmed access to an engineer's laptop and said Sitel's access created a maximum potential impact for 366 customers.

The leaked Mandiant material adds a chronology to that sequence: Sitel notified Okta in January, well before the late-March public disclosures. That timing makes the gap between vendor notice, investigation, and customer understanding the central issue.

First-order effects

  • Okta and Sitel face sharper scrutiny over incident handling because the reported January 25 notice and March 17 timeline predate Okta's public confirmation of the contractor-linked access.
  • Customers included in Okta's stated maximum potential-impact group gain a clearer basis to question when Okta understood the vendor incident and what exposure information was available.

Second-order effects

  • Okta's later finding that the intrusion lasted 25 consecutive minutes and affected two active customers, reported in its completed vendor-breach probe, must be assessed against the earlier notification chronology rather than only the final scope.
  • Identity-service customers and their security teams are likely to place greater weight on how quickly a provider converts a contractor's alert into a usable exposure assessment.

Third-order effects

  • Third-party access becomes a more consequential governance issue for identity providers: vendor notification and escalation records can shape customer trust as much as the eventual technical scope of an intrusion.
  • The episode points toward security accountability extending across the provider-subprocessor chain, with incident-response speed becoming part of how enterprise buyers evaluate identity vendors.

The trend: Identity-security vendors are being judged not only on breach containment, but on the speed and clarity with which contractor incidents are escalated to affected customers.

Discussion

  • @billdemirkapi Bill Demirkapi on x
    New documents for the Okta breach: I have obtained copies of the Mandiant report detailing the embarrassing Sitel/SYKES breach timeline and the methodology of the LAPSUS$ group. 1/N https://twitter.com/... https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    New documents offer the most detailed account so far of how the Lapsus$ group hacked Sitel, including how the hackers accessed a spreadsheet of ‘domain admin’ passwords on Sitel's network at the time they were compromising Okta. https://techcrunch.com/...
  • @zackwhittaker Zack Whittaker on x
    According to a timeline of the Sitel intrusion compiled by Mandiant (dated March 17), the Lapsus$ hackers accessed a spreadsheet on Sitel's internal network called “DomAdmins-LastPass.xlsx” early on January 21, around the time Okta was compromised. https://techcrunch.com/...
  • @billdemirkapi Bill Demirkapi on x
    I have been terminated from Zoom for refusing to remove the following tweets. Anyone have recommendations for wrongful termination lawyers based in California? https://twitter.com/...
  • @billdemirkapi Bill Demirkapi on x
    My questions for Okta: You knew that the machine of one of your customer support members was compromised back in January. Why didn't you investigate it? Having the capability to detect an attack is useless if you aren't willing to respond. 7/N
  • @billdemirkapi Bill Demirkapi on x
    Good questions to ask include: Who knows how your sub-processors handle their own security? As we saw in this case, Sitel didn't take the security of their environment very seriously. What can an attacker do if one of your sub-processors becomes compromised? 11/N
  • @billdemirkapi Bill Demirkapi on x
    LAPSUS$ used off-the-shelf tooling from GitHub for the majority of their attacks. After downloading Process Explorer and Process Hacker, LAPSUS$ bypassed the FireEye endpoint agent by simply terminating it! 3/N https://twitter.com/...
  • @ninjaparanoid @ninjaparanoid on x
    Not surprised by this as a similar thing happened to me when I was in Mandiant. Most companies try to control what their employees post even if it's not related to their organization. I was about to get terminated too, but I decided to delete my tweets. One of the reasons I left.…
  • @lilyhnewman Lily Hay Newman on x
    just continues to be extremely unclear why Okta and its sub-processor Sitel apparently didn't have a greater sense of urgency about investigating this breach and its implications for their customers https://www.wired.com/...
  • @billdemirkapi Bill Demirkapi on x
    We can see how LAPSUS$ originally began investigating their compromised host on January 19th, 2022. With little regard for OPSEC, LAPSUS$ searched for a CVE-2021-34484 bypass on their compromised host and downloaded the pre-built version from GitHub. 2/N https://twitter.com/... h…
  • @racheltobac Rachel Tobac on x
    A reminder that passwords stored *in a password manager* are great... Passwords exported from a password manager into a spreadsheet saved on the network as DomAdmins-LastPass.xlsx...not great at all. https://twitter.com/...
  • @cyb3rops @cyb3rops on x
    What's the first thing advanced threat groups do after the first successful login on a target system with low privileges? Correct, they use the local browser to run a Bing search for privilege escalation tools on Github. https://twitter.com/... https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    Okta was unable to comment when reached prior to publication. Sitel and Mandiant did not dispute the contents of the reports but declined to comment when spokespeople were reached.
  • @zackwhittaker Zack Whittaker on x
    “It is also unclear why [Sitel and Okta] do not seem to have mounted more expansive and urgent responses while Mandiant's investigation was ongoing.” https://wired.com/... https://twitter.com/...
  • @gentilkiwi @gentilkiwi on x
    Your best security measure is to block Bing search. Or I missed something? https://twitter.com/...
  • @evanderburg Eric Vanderburg on x
    New Lapsus$ Hack Documents Make Okta's Response Look More Bizarre https://securitytc.com/SMXNtC https://twitter.com/...
  • @kostastsale Kostas on x
    I don't even know where to start... Fireeye endpoint terminated using Process Explorer, Bing search looking for Mimikatz, the two month response time? Oh boy, so many things to unravel here 😂 Very nice thread and juicy info 👇 https://twitter.com/...
  • @quentynblog Quentyn Taylor on x
    I am amazed that the mandiant report into the okta / sitel hack seems to have leaked. Unless the leak was deliberate, I consider this to be more serious than the original hack.... It shows a breakdown of any kind of confidentiality, though to be fair its an interesting report
  • @billdemirkapi Bill Demirkapi on x
    With the endpoint agent disabled, LAPSUS$ simply downloaded the official version of Mimikatz (a popular credential dumping utility) directly from its repository. 4/N https://twitter.com/...
  • @_mg_ @_mg_ on x
    This shows a lot of layers of security breakdown happening here. This is bigger than Okta. I promise that a lot of these fails are easily observed at many companies. Take notes, learn, improve. https://twitter.com/...
  • @troyhunt Troy Hunt on x
    Looks like some eating of humble pie, responses to Okta over their handling of this have not been kind: https://twitter.com/...
  • @vickerysec Chris Vickery on x
    Sign of a super-sophisticated Advanced Persistent Threat actor: “Bing search for Mimikatz” (for the non-tech-savvy, my words above are dripping with sarcasm) https://twitter.com/... https://twitter.com/...
  • @_rastamouse @_rastamouse on x
    I can't even.... https://twitter.com/...
  • @viss @viss on x
    they broke in, then used the victim network (okta) to bing search for privesc tools. WOW. https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    Microsoft got me to remove tweets about Mandiant (praising them) and about Exchange (during ProxyLogon). Gotta control the message. https://twitter.com/...
  • @mjg59 Matthew Garrett on x
    Looking at https://twitter.com/..., it's interesting to think about the degree to which modern security controls would have helped mitigate this attack. It's also important to note that what many people think of as ZTA would have been no help at all.
  • @racheltobac Rachel Tobac on x
    Many reasons why a person may have made this mistake — maybe they didn't understand that a group password manager would have allowed them to share the relevant passwords with their colleagues safely, maybe they didn't get that downloading & storing pws this way is not secure...
  • @viss @viss on x
    everyone on a redteam is walking on eggshells, doing insane opsec stuff seen in practically-only-nation-state- level campaigns, but the big hacks? they break in with stolen creds, openly search for tools on the victim network, and download commonly available tools.
  • @ravirockks Ravi Nayyar on x
    ‘Sitel and Mandiant did not dispute the contents of the reports but declined to comment’. Well, well, well.
  • @chvancooten Cas van Cooten on x
    Not sure what's more shocking, the “DomAdmins-LastPass.xlsx” file or that the attackers used BING to look up privilege escalation tools on a compromised machine 😅 https://twitter.com/...
  • @corg_e @corg_e on x
    “Bing search for privesc tools” 🤡😂 https://twitter.com/...
  • @alexstamos Alex Stamos on x
    Congrats to the Microsoft Bing team for being the favorite search engine of the LAPSUS$ kids looking for mimikatz. https://twitter.com/...