iTnews Asia
  • Home
  • News
  • Security

Okta's data breach bigger than first thought

Okta's data breach bigger than first thought

All customer service contact details leaked.

By Richard Chirgwin on Nov 30, 2023 12:55PM

Okta has discovered that it underestimated the reach of a late September data breach.

The company has not put a number to the full scale of the breach, but in a just-published update to its root cause analysis, Okta said “all customer support system users” had personal information leaked in the breach.

In an earlier post, Okta’s CISO David Bradbury had said just 134 individuals, less than one percent of its customers, had been breached.

The breach covers users of Okta’s workforce identity cloud (WIC) and customer identity solution (CIS) products, “except customers in our FedRamp High and DoD IL4 environments”.

In addition, the Auth0/CIC case management system was not impacted.

Bradbury’s latest post said the attacker created a report containing 15 fields, which were blank for most records: “For 99.6 percent of users in the report, the only contact information recorded is full name and email address.”

The report did not include user credentials or sensitive personal data, Okta said.

Okta recommends that all users of the customer support system implement multi-factor authentication (94 percent already have, the post stated).

Other recommended mitigations include implementing session binding (which requires reauthentication if an admin’s session is reused across more than one Autonomous System number); admin session timeouts; and phishing awareness.

Okta said in the original attack, beginning on September 28, the threat actor accessed files associated with 134 customers, including HAR files that contained session tokens. 

They then used those tokens to hijack the sessions of five customers, giving the attacker the access they used to run the report.

The threat actor most likely launched their attack using an Okta employee’s credentials that were stored in their personal Google account.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
data breach okta security

Related Articles

  • Proofpoint CEO: A tool-based approach for cybersecurity is impractical
  • Akamai: AI-security is both a security imperative and an economic necessity
  • The real-life Tom & Jerry chase
  • How can we bolster our resilience against AI-enabled e-mail attacks?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

Akamai: AI-security is both a security imperative and an economic necessity

Akamai: AI-security is both a security imperative and an economic necessity

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.