logo

Swimming past 2FA, part 1: How to spot an Okta MITM phishing attack

ID: b6b88173-d989-52b2-a9f5-431af6ba5e20

STIX ID: report--b6b88173-d989-52b2-a9f5-431af6ba5e20

Feed Name: Expel Blog

Threat Score
55/100

Date Published: 2021-07-13

Date Updated: 2026-04-27

Author: Joshua Kim; Evan Reichard; Ashwin Ramesh

...
...

This blog post details an Okta-targeted credential-phishing campaign where attackers sent phishing links (via SendGrid) to fake Okta login pages and a malicious Duo MFA page to bypass MFA using a MITM workflow; it covers how responders detected the compromise by correlating Duo access and authentication device IPs and using geo-distance checks, highlights telltale signs of the fake pages, and provides prevention and detection recommendations for organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.