Lapsus$ Threat Actor Demonstrates Access to Backend Okta Tooling
ID: 613b3e7c-d909-546c-8e68-9c2e615b63f6
STIX ID: report--613b3e7c-d909-546c-8e68-9c2e615b63f6
Feed Name: Kudelski Security
Okta disclosed a security incident in mid-January 2022 attributed to the Lapsus$ group in which an attacker accessed a contractor support engineer's laptop (Jan 16–21), potentially allowing password and MFA resets and impacting approximately 2.5% of core Okta customers; Okta investigated and contained the event, notified impacted customers, and the CFC (Kudelski Security) recommends searching logs for account/MFA changes, suspending suspect accounts, and engaging incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
