logo

Swimming past 2FA, part 2: How to investigate Okta compromise

ID: 6d29aeae-3a59-557d-91ed-3a9e1a1afc98

STIX ID: report--6d29aeae-3a59-557d-91ed-3a9e1a1afc98

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2021-08-31

Date Updated: 2026-04-27

Author: Ashwin Ramesh

...
...

This post documents an investigation of an Okta MITM phishing incident where stolen Okta credentials allowed an attacker to access G Suite via SSO and download sensitive Google Drive files; the report walks through Okta and Google Drive audit logs that show the activity, identifies a malicious IP used by the attacker, describes automated workflows used to quickly enumerate file access and impacted accounts, and recommends immediate remediation (reset credentials, force logout/clear sessions) and adoption of phish-resistant MFA (FIDO/WebAuthn).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.