The encyclopedia · Software & IT · Operational decision · 2022
Okta's support engineer was screen-shared into — and 366 customers were breached
In 2022, hackers accessed an Okta support engineer's screen via a remote session. 366 customer organizations were potentially compromised.
Okta · 2022-10
What happened
In October 2022, Okta, a major identity and access management provider, disclosed that hackers had accessed its systems through a third-party customer support engineer. The hackers, linked to the Lapsus$ group, gained access to the engineer's screen during a remote support session and used that access to view Okta's internal systems.
The breach potentially affected 366 of Okta's customer organizations — approximately 2.5% of its customer base. Because Okta is an identity provider (managing login credentials for other companies), the breach had a cascading risk: if the hackers could access Okta's systems, they could potentially access the systems of Okta's customers.
Okta was criticized for its slow and incomplete disclosure of the breach. The company initially downplayed the scope, then revised its estimates upward. The case illustrated how a breach at an identity provider is qualitatively different from a breach at a regular company: the identity provider is the keys to the kingdom, and a compromise of the key master is a compromise of every door it opens.
Why it happened
- Hackers accessed an Okta support engineer's screen via a remote session.
- 366 customer organizations were potentially compromised through the identity provider.
- Okta's disclosure was slow and initially downplayed the scope.
- A breach at an identity provider has cascading risk across all customers.
The lesson
An identity provider is the keys to the kingdom. A breach at Okta is a potential breach at every company that uses it. The key master's lock must be the strongest.
Aftermath
Okta overhauled its support security and disclosure processes. The case prompted enterprise customers to review their identity provider dependencies. It is cited alongside SolarWinds and MOVEit as an example of supply chain risk in identity infrastructure.
Sources
spotted an error? The club wants to know.
More like this
Hackers hid in SolarWinds' update — 18,000 organizations installed the backdoor
LastPass was hacked twice in 2022 — the second breach exposed password vaults
Hackers exploited zero-days in Microsoft Exchange — and 250,000 servers were compromised
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.