logo

Okta warns of "unprecedented" credential stuffing attacks on customers

ID: d1a68461-9ef0-59e6-b8ed-9132e2f0e1f8

STIX ID: report--d1a68461-9ef0-59e6-b8ed-9132e2f0e1f8

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Okta has observed an "unprecedented" spike in credential stuffing attacks leveraging TOR and residential proxy services (e.g., NSOCKS, DataImpulse) that successfully breached accounts for a small percentage of customers. The attacks were particularly effective against organizations using the Okta Classic Engine with ThreatInsight set to Audit-only and those that do not block anonymizing proxies; Okta recommends enabling ThreatInsight in Log and Enforce mode, denying anonymizing proxies, adopting Okta Identity Engine, multi-factor or passwordless authentication, and implementing Dynamic Zones and IP blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.