logo

Okta Under Siege Attackers Call Help Desks To Bypass MFA and Steal SaaS Data

ID: d21e1fc5-6ba3-5469-a88b-482d8962e388

STIX ID: report--d21e1fc5-6ba3-5469-a88b-482d8962e388

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: Varshini

...
...

Attackers are increasingly using 'Okta vishing'—voice phishing and social engineering against users and help desks—to manipulate or reset MFA and gain SSO access to cloud SaaS environments. This enables immediate access to Microsoft 365, SharePoint, OneDrive, Google Workspace, Salesforce, Slack and other tenant resources, often resulting in direct data theft, mailbox forwarding/persistence and OAuth abuses. The report outlines the attack flow (reconnaissance, social-engineering call, MFA manipulation, SSO pivot, data theft), impacted assets, and mitigations including stronger verification, phishing-resistant MFA (FIDO2/passkeys), conditional access, help-desk training, and improved detection and playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.