Okta gibt weitere Auswirkungen der Sicherheitslücke im Support-System vom Oktober 2023 bekannt

Teilen:

Identity services provider Okta has disclosed that it detected “additional threat actor activity” in connection with the October 2023 breach of its support case management system.

“The threat actor downloaded the names and email addresses of all Okta customer support system users,” the company said in a statement shared with The Hacker News.

“All Okta Workforce Identity Cloud (WIC) and Customer Identity Solution (CIS) customers are impacted except customers in our FedRamp High and DoD IL4 environments (these environments use a separate support system NOT accessed by the threat actor). The Auth0/CIC support case management system was not impacted by this incident.”

On top of that, the adversary is believed to have accessed reports containing contact information of all Okta certified users, some Okta Customer Identity Cloud (CIC) customers, and unspecified Okta employee information. However, it emphasized that the data does not include user credentials or sensitive personal data.

News of the expanded scope of the breach was first reported by Bloomberg.

The company also told the publication that while it does not have any evidence of the stolen information being actively misused, it has taken the step of notifying all customers of potential phishing and social engineering risks.

It also stated that it “pushed new security features to our platforms and provided customers with specific recommendations to defend against potential targeted attacks against their Okta administrators.”

Okta, which has enlisted the help of a digital forensics firm to support its investigation, further said it “will also notify individuals that have had their information downloaded.”

The development comes more than three weeks after the identity and authentication management provider said the breach, which took place between September 28 to October 17, 2023, affected 1% – i.e., 134 – of its 18,400 customers.

The identity of the threat actors behind the attack against Okta’s systems is currently not known, although a notorious cybercrime group called Scattered Spider has targeted the company as recently as August 2023 to obtain elevated administrator permissions by pulling off sophisticated social engineering attacks.

According to a report published by ReliaQuest last week, Scattered Spider infiltrated an unnamed company and gained access to an IT administrator’s account via Okta single sign-on (SSO), followed by laterally moving from the identity-as-a-service (IDaaS) provider to their on-premises assets in less than one hour.

The formidable and nimble adversary, in recent months, has also evolved into an affiliate for the BlackCat ransomware operation, breaking into cloud and on-premises environments to deploy file-encrypting malware for generating illicit profits.

spider

“The group’s ongoing activity is a testament to the capabilities of a highly skilled threat actor or group having an intricate understanding of cloud and on-premises environments, enabling them to navigate with sophistication,” ReliaQuest researcher James Xiang said.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:18 am, Juni 21, 2025
Wetter-Symbol 19°C
L: 18° | H: 21°
klarer Himmel
Luftfeuchtigkeit: 74 %
Druck: 1019 mb
Wind: 6 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 3%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 21°°C 0.2 mm 20% 10 mph 64 % 1019 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 26°°C 0.34 mm 34% 15 mph 77 % 1013 mb 0 mm/h
Mo. Juni 23 10:00 pm
Wetter-Symbol
15° | 23°°C 0 mm 0% 14 mph 75 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
15° | 25°°C 0.2 mm 20% 14 mph 72 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
17° | 21°°C 1 mm 100% 10 mph 85 % 1011 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 25°°C 0 mm 0% 8 mph 64 % 1019 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
27° | 31°°C 0 mm 0% 9 mph 41 % 1018 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 10 mph 23 % 1016 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 9 mph 27 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0.2 mm 20% 5 mph 39 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
21° | 21°°C 0.34 mm 34% 7 mph 66 % 1013 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
19° | 19°°C 0.25 mm 25% 10 mph 77 % 1012 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 11 mph 66 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,725.41
-1.22%
Ethereum(ETH)
€2,103.00
-3.83%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.85
-0.97%
Solana(SOL)
€121.73
-3.39%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.141596
-2.93%
Shiba Inu(SHIB)
€0.000010
-1.49%
Pepe(PEPE)
€0.000009
-0.83%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen