The Okta before the storm?

Share This Post

The internet is a buzz today after data extortion group Lapsus$ posted screenshots on its Telegram channel. They claim the screenshots to be of Okta’s backend administrative consoles and customer data.

Worryingly, Lapsus$ claims to have not gone after Okta for their data, but to target Okta’s customers.

Okta claims that they have seen no evidence of continued breach after security incident which occurred in late January involving the account of a third party customer support engineer.

Companies who rely on Okta for identity management and authentication services are being instructed to ‘remain vigilant and on high alert’. Monitor user activity, especially that of privileged users and admins, and watch of unusual activity.

Okta has a white paper on Leveraging Identity Data in Cyber Attack Detection and Response, which could be helpful in the effort to be vigilant.

https://www.okta.com/resources/whitepaper/leveraging-identity-data-in-cyber-attack-detection-and-response/

If any meaningful IoCs or more information comes to light, we will share it here.





Reach out to our incident response team for help

More To Explore

Information Security News – 12/15/2025

CISA Warns Microsoft Windows Users—Log Out and Shut Down Article Link: https://www.forbes.com/sites/zakdoffman/2025/12/09/cisa-warns-microsoft-windows-users-log-out-and-shut-down/ Data Brokers are Exposing Medical Professionals, and Turning Their Personal Lives into Open

Information Security News – 12/8/2025

ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs into Spyware Article link: https://thehackernews.com/2025/12/shadypanda-turns-popular-browser.html University of Pennsylvania Joins Victims of Clop’s Oracle EBS Raid Article

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.