Okta, Inc. is a publicly traded identity and access management company based in San Francisco. It provides cloud software that helps companies manage and secure user authentication into applications, and for developers to build identity controls into applications, website web services and devices
- Wikipedia
On 03.22.22 it was confirmed by Microsoft that the LAPSUS$ extortion-focused hacking crew had gained "limited access" to its systems, as authentication services provider Okta revealed that nearly 2.5% of its customers have been potentially impacted in the wake of the breach.
- Hacker News
Since recording this episode on 03.22.22, it seems Okta has admitted to being breached per their own blog, updated 03.23.22.
"After a thorough analysis of these claims, we have concluded that a small percentage of customers – approximately 2.5% – have potentially been impacted and whose data may have been viewed or acted upon. We have identified those customers and are contacting them directly.
If you are an Okta customer and were impacted, we have already reached out directly by email. We are sharing this interim update, consistent with our values of customer success, integrity, and transparency." https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/
In this episode, we cover some of the facts as they were presented on 03.22.22. My colleague Stephen Kowski, Director of Global Sales Engineering and Information Security at IRONSCALES gave us some advice on how companies can investigate and protect themselves.
[UPDATE] Okta’s Investigation of the January 2022 Compromise
https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/
-----------------
We’re stronger together.
Keep connected with CyberSecurity Heroes at Apple Podcasts, Spotify, Stitcher and Google Podcast.
CyberSecurity Heroes is brought to you by IRONSCALES.
An email security platform powered by AI, enhanced by thousands of customer security teams and built around detecting and removing threats in the inbox.
We offer a service that is fast to deploy, easy to operate and is unparalleled in the ability to stop all types of email threats, including advanced attacks like BEC, ATO and more.
Learn more at ironscales.com