{"id":1903,"date":"2023-10-20T21:39:00","date_gmt":"2023-10-20T21:39:00","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/more-okta-customers-hacked-through-support-service"},"modified":"2023-10-20T21:39:00","modified_gmt":"2023-10-20T21:39:00","slug":"more-okta-customers-hacked","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/10\/20\/more-okta-customers-hacked\/","title":{"rendered":"More Okta Customers Hacked"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?w=640&#038;ssl=1\"><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked-1.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"40.321153846154\">\n<div readability=\"29.661538461538\">\n<p>Okta, an identity and access management services provider, disclosed that its customer support case management system was recently compromised, exposing sensitive customer data including cookies and session tokens. Attackers could potentially use the information to impersonate valid users contacting support.<\/p>\n<p>The customer support case management system is separate from the Okta service itself and the incident only impacted customers with recent support cases, the company&#8217;s <span>Chief Security Officer David Bradbury<a href=\"https:\/\/sec.okta.com\/harfiles\" target=\"_blank\" rel=\"noopener\"> stressed in a blog post<\/a> on Oct. 20. <\/span>Impacted customers have been notified, he said.<\/p>\n<p>&#8220;<span>Okta has worked with impacted customers to investigate, and has taken measures to protect our customers, including the revocation of embedded session tokens,&#8221; Bradbury added.<\/span><\/p>\n<p><span>In its blog post, Okta listed IP addresses and user-agents that security teams can use in their threat hunting efforts.<\/span><\/p>\n<p>The announcement comes after Okta was identified as the initial attack vector in recent twin <a href=\"https:\/\/www.darkreading.com\/application-security\/okta-flaw-involved-mgm-resorts-breach-attackers-claim\" target=\"_blank\" rel=\"noopener\">c<\/a><a href=\"https:\/\/www.darkreading.com\/application-security\/okta-flaw-involved-mgm-resorts-breach-attackers-claim\" target=\"_blank\" rel=\"noopener\">yberattacks on MGM Resorts and Caesars Entertainment<\/a>.<\/p>\n<\/div>\n<\/div>\n<div id=\"articleFooter-newsletterSignup\" readability=\"10.473404255319\">\n<p>Keep up with the latest cybersecurity threats, newly-discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.<\/p>\n<p><a class=\"subscribe-btn dr-btn\" href=\"https:\/\/darkreading.tradepub.com\/c\/pubRD.mpl?secure=1&amp;sr=pp&amp;_t=pp:&amp;qf=w_defa3135&amp;ch=dr_eoa\" title=\"Subscribe\" target=\"_blank\" rel=\"noreferrer noopener\">Subscribe<\/a><\/div>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/more-okta-customers-hacked-through-support-service\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Okta, an identity and access management services provider, disclosed that<\/p>\n","protected":false},"author":12,"featured_media":1904,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-1903","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?fit=342%2C343&ssl=1",342,343,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?fit=300%2C300&ssl=1",300,300,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?fit=342%2C343&ssl=1",342,343,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?fit=342%2C343&ssl=1",342,343,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?fit=342%2C343&ssl=1",342,343,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?fit=342%2C343&ssl=1",342,343,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?fit=342%2C343&ssl=1",342,343,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?resize=342%2C343&ssl=1",342,343,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?resize=342%2C343&ssl=1",342,343,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/more-okta-customers-hacked.jpg?fit=342%2C343&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1903","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1903"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1903\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/1904"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1903"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1903"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1903"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}