logo

Okta Warns of Phishing Attacks Mimic “Okta Support” to Steal MFA Tokens

ID: e77dce9f-21d3-5d01-85e9-774d80f8ac99

STIX ID: report--e77dce9f-21d3-5d01-85e9-774d80f8ac99

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2024-12-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Okta has warned of a sophisticated phishing campaign impersonating its support team to steal credentials, MFA tokens, photo IDs and password reset links from customers; attackers use real-time phishing kits, CAPTCHA evasion, precise SSO page cloning, and custom sites tied to victim phone numbers, and initially hosted infrastructure on Hostwinds/Hostinger before moving to a Russia-based provider. Okta clarified official email/SMS channels and urged reporting and stronger MFA and user education to mitigate the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.