Okta says hackers stole customer access tokens from support unit

Identification and entry large Okta stated a hacker broke into its buyer help ticket system and stole delicate information that can be utilized to interrupt into the networks of Okta’s prospects.

Okta chief safety officer David Bradbury stated in a weblog submit Friday {that a} hacker used a stolen credential to entry the corporate’s help case administration system, which contained browser recording information uploaded by Okta prospects for troubleshooting.

Browser recording periods (or HAR information) are used for diagnosing issues throughout an online looking session, and infrequently embrace web site cookies and session tokens, which if stolen can be utilized to impersonate an actual person account without having their password or two-factor.

Bradbury stated “prospects who have been impacted by this have been notified.” It’s not clear how Okta’s help case administration system was initially compromised.

Okta offers organizations and corporations with entry and id instruments, akin to “single sign-on,” which permits workers entry to all of an organization’s assets on the community with one set of credentials. Okta has round 17,000 prospects and manages round 50 billion customers, the corporate stated in a March 2023 weblog submit.

Okta spokesperson Vitor De Souza informed TechCrunch that round 1% of shoppers are affected by this breach, however declined to offer a particular quantity.

Safety agency BeyondTrust, which makes use of Okta, stated in its personal weblog submit that it notified Okta of a possible breach on October 2 after it detected an tried compromise to its community a short while after an administrator shared a browser recording session with an Okta help agent.

BeyondTrust’s chief know-how officer Marc Maiffret stated the hacker used a session token from the uploaded browser recording session to create an administrator account on BeyondTrust’s community, which it instantly shut down. Maiffret stated the incident “was the results of Okta’s help system being compromised which allowed an attacker to entry delicate information uploaded by their prospects.”

Safety journalist Brian Krebs first reported the information. Krebs reported that Okta contained the incident by October 17, citing the corporate’s deputy chief data safety officer Charlotte Wylie.

That is the most recent incident at Okta, which in 2022 stated that hackers stole a few of its supply code. Earlier in 2022, hackers posted screenshots exhibiting entry to the corporate’s inner community after hacking into an organization Okta used for customer support.

Okta’s inventory closed down 11% on Friday following information of the breach.

Learn extra on TechCrunch:

Leave a Reply