Okta and LAPSUS$: What you need to know
ID: faaa15ed-58a2-5708-b050-508bec86d47d
STIX ID: report--faaa15ed-58a2-5708-b050-508bec86d47d
Feed Name: Elastic Security Labs
Elastic summarizes LAPSUS$’s recent targeting of high-profile organizations (Nvidia, Samsung, Ubisoft, and Okta), notes Okta’s statements that a January 2022 incident potentially impacted ~2.5% of customers with limited console access (including the ability to reset MFA/passwords), and provides practical threat-hunting guidance for Okta logs in Elastic—covering ingestion (Okta module/Filebeat), example Lucene queries to detect suspicious activity, and links to detection rules and simulation tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
