Back to the archive

The encyclopedia · Software & IT · Operational decision · 2022

Okta's support engineer was screen-shared into — and 366 customers were breached

In 2022, hackers accessed an Okta support engineer's screen via a remote session. 366 customer organizations were potentially compromised.

Okta · 2022-10

What happened

In October 2022, Okta, a major identity and access management provider, disclosed that hackers had accessed its systems through a third-party customer support engineer. The hackers, linked to the Lapsus$ group, gained access to the engineer's screen during a remote support session and used that access to view Okta's internal systems.

The breach potentially affected 366 of Okta's customer organizations — approximately 2.5% of its customer base. Because Okta is an identity provider (managing login credentials for other companies), the breach had a cascading risk: if the hackers could access Okta's systems, they could potentially access the systems of Okta's customers.

Okta was criticized for its slow and incomplete disclosure of the breach. The company initially downplayed the scope, then revised its estimates upward. The case illustrated how a breach at an identity provider is qualitatively different from a breach at a regular company: the identity provider is the keys to the kingdom, and a compromise of the key master is a compromise of every door it opens.

Why it happened

  • Hackers accessed an Okta support engineer's screen via a remote session.
  • 366 customer organizations were potentially compromised through the identity provider.
  • Okta's disclosure was slow and initially downplayed the scope.
  • A breach at an identity provider has cascading risk across all customers.
What it cost366 customers potentially compromised; brand damagecostly

The lesson

An identity provider is the keys to the kingdom. A breach at Okta is a potential breach at every company that uses it. The key master's lock must be the strongest.

Aftermath

Okta overhauled its support security and disclosure processes. The case prompted enterprise customers to review their identity provider dependencies. It is cited alongside SolarWinds and MOVEit as an example of supply chain risk in identity infrastructure.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →