The LAPSUS$ extortion group claimed access to Okta through a compromised third-party support engineer’s endpoint and published screenshots of internal communications, administrative tools, customer-management systems, and customer-account interfaces. Okta said the intrusion occurred in January 2022; its initial assessment stated the endpoint could not create or delete users or download customer information, but could reset user passwords and MFA factors.
Okta later revised its impact assessment, saying roughly 2.5% of customers may have been affected. Organizations should review retained Okta System Log records for password or MFA resets, primary-email changes, privilege grants, and administrative impersonation, particularly activity associated with support workflows. Elastic reported it had not identified malicious activity tied to the incident in its own investigations.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Okta said a system used by a subprocessor or third-party support engineer was compromised. The endpoint could reset user passwords and MFA factors, though Okta said the attacker did not obtain those credentials or factors.
Okta corrected its earlier assessment and said that approximately 2.5% of its customer base could potentially have been affected by the incident.
LAPSUS$ claimed it accessed Okta through the third-party support-engineer endpoint and published screenshots purportedly showing internal communications, administrative tools, customer-management tools, and customer accounts. The group said its interest was access to Okta customers rather than Okta itself.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.