Security News

Okta breach: Hackers stole info on ALL customer support users
2023-11-29 11:13

The scope of the recent breach of the Okta customer support system is much wider than initially established, the company has admitted on Tuesday: the attackers downloaded a report that contained the names and email addresses of all Okta customer support system users. Initial and latest findings about the Okta customer support system breach.

Okta Discloses Broader Impact Linked to October 2023 Support System Breach
2023-11-29 06:18

Identity services provider Okta has disclosed that it detected "additional threat actor activity" in connection with the October 2023 breach of its support case management system. "The threat...

Okta breach post mortem reveals weaknesses exploited by attackers
2023-11-06 14:11

The recent breach of the Okta Support system was carried out via a compromised service account with permissions to view and update customer support cases. The threat actor took advantage of the access they had gained to the Okta Support system and to unsanitized HAR files provided by the customers to Okta Support.

Okta October breach affected 134 orgs, biz admits
2023-11-06 14:01

Infosec in brief Okta has confirmed details of its October breach, reporting that the incident led to the compromise of files belonging to 134 customers, "Or less than 1 percent of Okta customers." Okta's report on the breach confirms much of what was previously known, but provides the first set of solid numbers of those affected, and notes that five of its 134 affected customers experienced their own intrusions - at least that Okta knows of.

Okta's Recent Customer Support Data Breach Impacted 134 Customers
2023-11-04 06:03

Identity and authentication management provider Okta on Friday disclosed that the recent support case management system breach affected 134 of its 18,400 customers. It further noted that the...

Okta breach: 134 customers exposed in October support system hack
2023-11-03 14:18

Okta says attackers who breached its customer support system last month gained access to files belonging to 134 customers, five of them later being targeted in session hijacking attacks with the help of stolen session tokens. "From September 28, 2023 to October 17, 2023, a threat actor gained unauthorized access to files inside Okta's customer support system associated with 134 Okta customers, or less than 1% of Okta customers," Okta revealed.

Okta tells 5,000 of its own staff that their data was accessed in third-party breach
2023-11-02 15:37

Okta has sent out breach notifications to almost 5,000 employees, warning them that miscreants breached one of its third-party vendors and stole a file containing staff names, social security numbers, and health or medical insurance plan numbers. The third-party, Rightway Healthcare, helps people compare healthcare providers and rates, and this includes Okta employees and their families.

Okta hit by third-party data breach exposing employee information
2023-11-02 14:09

Okta is warning nearly 5,000 current and former employees that their personal information was exposed after a third-party vendor was breached. The data breach notification warns of a security incident that impacted Rightway Healthcare, which provides healthcare coverage for Okta employees and their families.

Okta data breach exposed personal information of employees
2023-11-02 14:09

Okta is warning nearly 5,000 current and former employees that their personal information was exposed after a third-party vendor was breached. The data breach notification warns of a security incident that impacted Rightway Healthcare, which provides healthcare coverage for Okta employees and their families.

Week in review: VMware patches critical vulnerability, 1Password affected by Okta breach
2023-10-29 09:00

1Password also affected by Okta Support System breachFollowing in the footsteps of BeyondTrust and CloudFlare, 1Password has revealed that it has been affected by the Okta Support System breach. Microsoft announces wider availability of AI-powered Security CopilotMicrosoft Security Copilot has been made available to a larger number of enterprise customers, via an invitation-only Early Access Program.