logo

Lapsus$ Threat Actor Demonstrates Access to Backend Okta Tooling

ID: 613b3e7c-d909-546c-8e68-9c2e615b63f6

STIX ID: report--613b3e7c-d909-546c-8e68-9c2e615b63f6

Feed Name: Kudelski Security

Threat Score
70/100

Date Published: 2022-04-04

Date Updated: 2026-07-22

...
...

Okta disclosed a security incident in mid-January 2022 attributed to the Lapsus$ group in which an attacker accessed a contractor support engineer's laptop (Jan 16–21), potentially allowing password and MFA resets and impacting approximately 2.5% of core Okta customers; Okta investigated and contained the event, notified impacted customers, and the CFC (Kudelski Security) recommends searching logs for account/MFA changes, suspending suspect accounts, and engaging incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.