The Okta before the storm?

Share This Post

The internet is a buzz today after data extortion group Lapsus$ posted screenshots on its Telegram channel. They claim the screenshots to be of Okta’s backend administrative consoles and customer data.

Worryingly, Lapsus$ claims to have not gone after Okta for their data, but to target Okta’s customers.

Okta claims that they have seen no evidence of continued breach after security incident which occurred in late January involving the account of a third party customer support engineer.

Companies who rely on Okta for identity management and authentication services are being instructed to ‘remain vigilant and on high alert’. Monitor user activity, especially that of privileged users and admins, and watch of unusual activity.

Okta has a white paper on Leveraging Identity Data in Cyber Attack Detection and Response, which could be helpful in the effort to be vigilant.

https://www.okta.com/resources/whitepaper/leveraging-identity-data-in-cyber-attack-detection-and-response/

If any meaningful IoCs or more information comes to light, we will share it here.





Reach out to our incident response team for help

More To Explore

Information Security News – 5/12/2025

Microsoft Sets Passkeys Default for New Accounts Article Link: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html Accenture: What We Learned When Our CEO Got Deepfaked Article Link: https://www.computing.co.uk/event/2025/accenture-what-we-learned-when-our-ceo-got-deepfaked Ghost Students Creating

Information Security News – 5/5/2025

Cloudflare Sees a Big Jump in DDoS Attacks Article Link: https://www.bleepingcomputer.com/news/security/cloudflare-mitigates-record-number-of-ddos-attacks-in-2025/ Bring Your Own Computer Trend Gives Cyber Pros Chills, Yet It’s Here to Stay

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.