Okta Under Attack as Hackers Skip Phishing for Identity Systems
ID: a54096a4-cb22-52aa-86bf-0121c55c44a7
STIX ID: report--a54096a4-cb22-52aa-86bf-0121c55c44a7
Feed Name: GBHackers
Attackers are increasingly using voice‑based social engineering ('Okta vishing') to trick employees and help desks into resetting MFA, enrolling attacker devices, or approving push notifications, which lets them gain control of identity providers (e.g., Okta) and immediately pivot via SSO into cloud services (Microsoft 365, SharePoint, OneDrive, Google Workspace, Salesforce, Slack) to exfiltrate data. The report outlines the reconnaissance and vishing call flow, detection clues for identity and SaaS telemetry, and defensive recommendations such as strict verification for MFA resets, banning legacy auth, restricting OAuth consent, mandating phishing‑resistant MFA, and having SOC playbooks to revoke sessions and remove rogue factors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
