logo

Okta SSO accounts targeted in vishing-based data theft attacks

ID: b8f7b6a6-951f-57db-a2e6-0415ea0d5a25

STIX ID: report--b8f7b6a6-951f-57db-a2e6-0415ea0d5a25

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-01-22

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Okta warns of commercially sold vishing phishing kits used in active campaigns to perform live adversary-in-the-middle attacks against identity providers (including Okta), enabling attackers to interact via phone calls, manipulate phishing pages in real time, capture SSO credentials and MFA codes, bypass push-based MFA, access victims' Okta dashboards to exfiltrate data (notably from services like Salesforce), and subsequently extort affected organizations; Okta recommends using phishing-resistant MFA such as FIDO2/passkeys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.