Business
Hackers stole customer access tokens from Okta’s support unit, admits firm

San Francisco, Oct 21
Identity and access company Okta has identified “adversarial activity†that leveraged access to a stolen credential to access Okta's support case management system.
The threat actor was able to view files uploaded by certain Okta customers as part of recent support cases, admitted Okta chief security officer David Bradbury.
“It should be noted that the Okta support case management system is separate from the production Okta service, which is fully operational and has not been impacted,†he mentioned in a blog post late on Friday.
All customers who were impacted in the security breach have been notified by the company.
Okta provides companies with access and identity tools, such as “single sign-onâ€. It has more than 18,000 customers with more than 7,000 integrations.
Bradbury said that Okta support will ask customers to upload an HTTP Archive (HAR) file, which allows for troubleshooting of issues by replicating browser activity.
“HAR files can also contain sensitive data, including cookies and session tokens, that malicious actors can use to impersonate valid users. Okta has worked with impacted customers to investigate, and has taken measures to protect our customers, including the revocation of embedded session tokens,†he informed.
Security firm BeyondTrust, which uses Okta, said that it notified the company of a potential breach on October 2 after it detected an attempted compromise to its network.
The incident began when BeyondTrust security teams detected an attacker trying to access an in-house Okta administrator account using a valid session cookie stolen from Okta’s support system.
“BeyondTrust’s own Identity Security Insights tool alerted the team of the attack, and they were able to block all access and verify that that attacker did not gain access to any systems,†said the company.
Okta is recommending its customers to sanitise all credentials and cookies/session tokens within a HAR file before sharing it.

2 hours ago
Our foreign policy, diplomacy have completely failed: Imran Masood slams govt after Prez Trump’s H-1B visa fee hike

2 hours ago
Congress criticises US President Trump, Centre's policies over H-1B visa fee hike

2 hours ago
Miami City Commission will open with hymns from Rig-Veda, Upanishads, Bhagavad-Gita

3 hours ago
The great American dream may now be too expensive to achieve

4 hours ago
Netizens react to Deepika Padukone's cryptic note: 'People matter more than success'

5 hours ago
Mallika Sherawat: Mahesh Bhatt saw my fire even before I did

5 hours ago
Tim Burton, Monica Bellucci announce split after two years together

5 hours ago
After exiting ‘Kalki 2898 AD’ sequel, Deepika Padukone shoots for SRK-starrer ‘King’

5 hours ago
‘I repeat, India has a weak PM’: Rahul Gandhi on H-1 B visa fee hike

5 hours ago
Global Ayyappa congregation gets more brickbats than bouquets

5 hours ago
Rahul Gandhi in Wayanad hints ‘hydrogen bomb’ is round the corner

5 hours ago
President Droupadi Murmu performs 'pind daan' at Gayaji

5 hours ago
US turning screws on India: Manish Tewari on H-1B visa fee hike