logo

Okta Warns of Credential Stuffing Attacks Targeting Customer Identity Cloud

ID: afa384a5-c14d-5964-97e8-fcda8b6a52e2

STIX ID: report--afa384a5-c14d-5964-97e8-fcda8b6a52e2

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2024-05-30

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Okta warned that a cross-origin authentication feature in its Customer Identity Cloud has been targeted by credential stuffing attacks beginning April 15, 2024; customers with the feature enabled were proactively notified. The advisory lists relevant log events to monitor (fcoa, scoa, pwd_leak), recommends rotating credentials, restricting or disabling cross-origin authentication, enabling breached password detection or Credential Guard, enforcing stronger authentication (passkeys/passwordless) and other mitigations to reduce the risk of account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.