logo

Okta cross-tenant impersonation: a new Expel detection

ID: d1098c59-bc15-5eff-91be-941cdcf3646c

STIX ID: report--d1098c59-bc15-5eff-91be-941cdcf3646c

Feed Name: Expel Blog

Threat Score
75/100

Date Published: 2023-10-31

Date Updated: 2026-04-27

Author: Chandler Matthews

...
...

Expel analyzed Okta’s disclosure of a novel cross-tenant impersonation technique—where attackers social-engineer IT staff to reset MFA on admin accounts, escalate privileges, and create malicious identity providers—to develop and tune two high-fidelity detections (Okta Suspicious Admin Activity Correlation and Okta Fastpass Phishing Attempt and Geo-infeasible Login Correlation) that correlate noisy events into actionable alerts and reduce false positives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.