logo

Lapsus$ Attack on Okta: How to Evaluate the Impact

ID: 60a685a0-1901-5d0f-8790-0d10812effa3

STIX ID: report--60a685a0-1901-5d0f-8790-0d10812effa3

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This ThreatLabz report details a Lapsus$ intrusion involving a compromised Okta third-party support engineer account in January 2022 that exposed information from up to 366 Okta customers. The report explains Lapsus$'s low-tech but effective methods (social engineering, SIM swapping, paid insiders), notes that Okta says the impact was limited and quickly mitigated, and provides Zscaler-specific SOC playbook steps, detection queries for SIEMs, and remediation/best-practice guidance for IDP customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.