Lapsus$ Attack on Okta: How to Evaluate the Impact
ID: 60a685a0-1901-5d0f-8790-0d10812effa3
STIX ID: report--60a685a0-1901-5d0f-8790-0d10812effa3
Feed Name: Zscaler Security Research Blog
This ThreatLabz report details a Lapsus$ intrusion involving a compromised Okta third-party support engineer account in January 2022 that exposed information from up to 366 Okta customers. The report explains Lapsus$'s low-tech but effective methods (social engineering, SIM swapping, paid insiders), notes that Okta says the impact was limited and quickly mitigated, and provides Zscaler-specific SOC playbook steps, detection queries for SIEMs, and remediation/best-practice guidance for IDP customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
