{"id":1991,"date":"2023-11-03T19:35:00","date_gmt":"2023-11-03T19:35:00","guid":{"rendered":"https:\/\/www.darkreading.com\/attacks-breaches\/okta-customer-support-breach-exposed-data-134-customers-"},"modified":"2023-11-03T19:35:00","modified_gmt":"2023-11-03T19:35:00","slug":"okta-customer-support-breach-exposed-data-on-134-companies","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/11\/03\/okta-customer-support-breach-exposed-data-on-134-companies\/","title":{"rendered":"Okta Customer Support Breach Exposed Data on 134 Companies"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?w=640&#038;ssl=1\"><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies-1.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p>Okta has confirmed that threat actors were able to breach its customer support system and steal files related to 134 of its customers, which is less than 1% of the identity and access management (IAM) company&#8217;s total roster. Out of those, Okta says cyberattackers went on to target five specific customers with the stolen data, including BeyondTrust, 1Password, and Cloudflare.<\/p>\n<p>The <a href=\"https:\/\/www.darkreading.com\/application-security\/more-okta-customers-hacked-through-support-service\" target=\"_blank\" rel=\"noopener\">stolen customer support files<\/a> were HAR files containing session tokens, Okta&#8217;s chief security officer David Bradbury explained in a detailed blog post about the incident this week.<\/p>\n<p>An investigation into the hack revealed an Okta employee&#8217;s credentials were compromised on a personal device, which likely led to the initial breach.<\/p>\n<p>&#8220;<span>During our investigation into suspicious use of this account, <a href=\"https:\/\/www.darkreading.com\/cloud\/hackers-target-high-privileged-okta-accounts-via-help-desk\" target=\"_blank\" rel=\"noopener\">Okta Security<\/a> identified that an employee had signed-in to their personal Google profile on the Chrome browser of their Okta-managed laptop,&#8221; Bradbury explained. &#8220;The username and password of the service account had been saved into the employee\u2019s personal Google account.&#8221;<\/span><\/p>\n<p>According to a timeline of events provided by <a href=\"https:\/\/www.darkreading.com\/endpoint\/okta-post-exploit-method-exposes-user-passwords\" target=\"_blank\" rel=\"noopener\">Okta<\/a>, 1Password was the first customer to reach out to Okta with a report of suspicious activity on Sept. 29. By Oct. 2, BeyondTrust had reported a similar issue. By using those indicators of compromise and associated IP addresses, Bradbury said his team was able to identify other targeted customers, including Cloudflare.<\/p>\n<p>All affected session tokens embedded in the compromised HAR files have since been revoked.<\/p>\n<p>Okta has also taken the step of blocking any future Google Chrome sign-ins on Okta-managed laptops using a personal Google account. Furthermore, the company added a feature tying Okta admin tokens to network location data, Bradbury added.<\/p>\n<p>&#8220;<span>Okta has released session token binding based on network location as a product enhancement to combat the threat of session token theft against Okta administrators,&#8221; Bradbury reassured Okta customers. &#8220;Okta administrators are now forced to re-authenticate if we detect a network change.&#8221;<\/span><\/p>\n<p>The detailed explanation from Okta comes after a series of brutal cybersecurity incident plagued the company, including being used to <a href=\"https:\/\/www.darkreading.com\/application-security\/okta-flaw-involved-mgm-resorts-breach-attackers-claim\" target=\"_blank\" rel=\"noopener\">breach MGM Resorts<\/a>. Most recently, Okta&#8217;s employee data was compromised through a <a href=\"https:\/\/www.darkreading.com\/remote-workforce\/okta-employee-data-exposed-third-party-vendor\" target=\"_blank\" rel=\"noopener\">third-party healthcare vendor<\/a>.<\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/okta-customer-support-breach-exposed-data-134-customers-\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Okta has confirmed that threat actors were able to breach<\/p>\n","protected":false},"author":12,"featured_media":1992,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-1991","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?fit=641%2C796&ssl=1",641,796,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?fit=242%2C300&ssl=1",242,300,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?fit=640%2C795&ssl=1",640,795,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?fit=640%2C795&ssl=1",640,795,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?fit=641%2C796&ssl=1",641,796,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?fit=641%2C796&ssl=1",641,796,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?fit=641%2C796&ssl=1",641,796,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?resize=641%2C575&ssl=1",641,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/okta-customer-support-breach-exposed-data-on-134-companies.jpg?fit=641%2C796&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1991"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1991\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/1992"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}