Leaked documents indicate the LAPSUS$ extortion group compromised Sykes Enterprises, an Okta subprocessor owned by Sitel Group, and maintained access from January 16 to January 21 while using tools including Mimikatz and disabling security controls. Screenshots later published by the group appeared to show access to an Okta support engineer’s workstation, prompting scrutiny of whether attackers could use that access to interact with customer tenants through support channels rather than by breaching Okta’s core service directly.
Okta said its own service was not directly breached, but later acknowledged it should have communicated and acted faster after receiving Sitel’s summary report on March 17, days before LAPSUS$ published evidence of the intrusion. The company said the maximum potential impact reached 366 customers, while leaked customer notifications and an intrusion timeline raised broader concerns about Sitel/Sykes’ security posture and Okta’s handling of the incident disclosure.

See attribution, scope, and your downstream exposure.
10 events from the most recent confirmed update back to the earliest known activity.
The reference states that LAPSUS$ targeted Globant and that the attack became public on March 30, 2022. Globant acknowledged unauthorized access to a limited section of its code repository, with source code and project documentation for a very limited number of clients exposed.
By March 28, 2022, Okta said it should have moved more quickly after receiving information about the incident and stated that the maximum potential impact reached 366 customers. The reassessment followed criticism of its initial handling and messaging.
After learning of the Okta-related compromise on March 22, 2022, Cloudflare opened an incident investigation, suspended potentially affected accounts, and forced password resets for 144 employees who had changed passwords or MFA settings since December 1, 2021. Cloudflare later said Okta confirmed there were no relevant malicious support-console events for Cloudflare instances and that it did not believe Cloudflare had been compromised.
Okta published an updated public statement on March 22, 2022, addressing the LAPSUS$ incident. In its response, the company acknowledged the issue involved a third-party support provider rather than a direct breach of Okta's core service.
On March 21, 2022, LAPSUS$ posted screenshots appearing to show access related to Okta support systems. The publication brought broad public attention to the earlier Sykes compromise.
Okta said it received Sitel's summary report about the Sykes intrusion on March 17, 2022. Leaked materials also reference a March 17 intrusion timeline reportedly produced by or based on data gathered by Mandiant.
Microsoft confirmed that LAPSUS$ gained limited access to its environment through a single compromised account and said no customer code or customer data was involved. The company said the account had been remediated and characterized the actor as focused on extortion and destructive activity rather than ransomware deployment.
A leaked customer notification indicates Sykes informed customers about the breach on January 25, 2022. The notice concerned the January compromise later linked to LAPSUS$.
Between January 16 and January 21, 2022, the attackers reportedly used common tools including Mimikatz and disabled security controls while operating in Sykes' environment. The activity was tied to the later-publicized incident involving Okta's subprocessor.
According to the leaked intrusion timeline, attackers were active in Sykes Enterprises' environment beginning on January 16, 2022. The compromise affected a Sykes employee account used to provide support for Okta customers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
cloudsek.com
Open sourcewired.com
Open sourcethehackernews.com
Open sourceokta.com
Open sourcemicrosoft.com
Open sourceblog.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.