Okta cross-tenant impersonation: a new Expel detection
ID: d1098c59-bc15-5eff-91be-941cdcf3646c
STIX ID: report--d1098c59-bc15-5eff-91be-941cdcf3646c
Feed Name: Expel Blog
Threat Score
Expel analyzed Okta’s disclosure of a novel cross-tenant impersonation technique—where attackers social-engineer IT staff to reset MFA on admin accounts, escalate privileges, and create malicious identity providers—to develop and tune two high-fidelity detections (Okta Suspicious Admin Activity Correlation and Okta Fastpass Phishing Attempt and Geo-infeasible Login Correlation) that correlate noisy events into actionable alerts and reduce false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
