logo

Top 7 recs for responding to the Lapsus$ breach claims

ID: 0a67f6ce-8a0e-5ed3-bd45-719eca2ad6c1

STIX ID: report--0a67f6ce-8a0e-5ed3-bd45-719eca2ad6c1

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2022-03-24

Date Updated: 2026-04-27

Author: Jonathan Hencinski

...
...

This advisory discusses the Okta/Lapsus$ compromise claims and Okta’s ongoing investigation (as of March 23, 2022), and provides seven prioritized recommendations—rotate privileged credentials and API tokens, restrict Okta support access, review admin/authentication logs for specific event types, enforce and expand MFA (prefer FIDO), configure network zones, establish/test incident response retainers and plans, and communicate transparently with stakeholders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.