Security News > 2022 > March > Microsoft and Okta confirm, detail impact of Lapsus$ gang’s attacks
Recent claims by the cyber extortion gang have been validated by Okta and Microsoft: Lapsus$ have managed to get their hands on some of Microsoft's source code and have gained access to the laptop of a support engineer working for a third-party contractor for Okta, allowing them to potentially impact approximately 2.5% of the company's customers.
After the gang published screenshots from Okta's internal systems and said that they focused their incursion on Okta customers, the company's CEO first said that, in late January 2022, they detected an attempt to compromise the account of a customer support engineer working for one of their subprocessors, and that "There is no evidence of ongoing malicious activity beyond the activity detected in January."
Later that day, David Bradbury, Okta's Chief Security Officer, first shared that "There was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer's laptop," that "The potential impact to Okta customers is limited to the access that support engineers have," and finally, that "a small percentage of customers - approximately 2.5% - have potentially been impacted and whose data may have been viewed or acted upon."
Okta did not name them and did not say what customer data may have been accessed.
Microsoft tracks Lapsus$ as DEV-0537 and confirmed that the gang does not use ransomware - for them it's all about extortion and destruction.
The attackers haven't been able to access customer code or data but did have access to the company's own source code - something that Microsoft doesn't consider a big deal, as it "Does not rely on the secrecy of code as a security measure."
News URL
https://www.helpnetsecurity.com/2022/03/23/microsoft-okta-lapsus/
Related news
- Microsoft still unsure how hackers stole MSA key in 2023 Exchange attack (source)
- Microsoft fixes two Windows zero-days exploited in malware attacks (source)
- Week in review: Palo Alto Networks firewalls under attack, Microsoft patches two exploited zero-days (source)
- Okta warns of "unprecedented" credential stuffing attacks on customers (source)
- Okta Warns of Unprecedented Surge in Proxy-Driven Credential Stuffing Attacks (source)
- New Latrodectus malware attacks use Microsoft, Cloudflare themes (source)
- Microsoft warns of "Dirty Stream" attack impacting Android apps (source)
- Week in review: PoCs allow persistence on Palo Alto firewalls, Okta credential stuffing attacks (source)
- Microsoft fixes Windows zero-day exploited in QakBot malware attacks (source)
- Microsoft fixes a bug abused in QakBot attacks plus a second under exploit (source)