0ktapus phishing campaign: How attackers abuse Okta SSO to bypass MFA
ID: fd0b8d1f-4ac3-5076-a140-458351ccbe6f
STIX ID: report--fd0b8d1f-4ac3-5076-a140-458351ccbe6f
Feed Name: ThreatLocker Blog
0ktapus is a large-scale phishing campaign that targets Okta Single Sign-On users with highly convincing lookalike IdP pages and real-time interception of credentials and MFA codes; captured data is replayed against legitimate Okta tenants to establish valid sessions and access connected SaaS ecosystems. The report attributes the campaign to Scattered Spider (UNC3944), notes impacts across 130+ organizations, describes TTPs (phishing, smishing, MFA fatigue, SSO abuse), and recommends mitigations including phishing-resistant MFA, domain monitoring, conditional access, session revocation, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
