EletiofeThe Third-Party Okta Hack Leaves Customers Scrambling

The Third-Party Okta Hack Leaves Customers Scrambling

-

- Advertisment -

Okta says that it is contacting customers who may have been impacted. On Tuesday, though, companies including the internet infrastructure firm Cloudflare raised the question of why they were hearing about the incident from tweets and criminal screenshots rather than from Okta itself. The identity management company seems to maintain, though, that compromising a third-party affiliate in some way is not a direct breach.

“In Okta’s statement, they said they were not breached and that the attacker’s attempts were ‘unsuccessful,’ yet they openly admit that attackers had access to customer data,” says independent security researcher Bill Demirkapi. “If Okta knew since January that an attacker may have been able to access confidential customer data, why did they never inform any of their customers?”

In practice, breaches of third-party service providers are an established attack path to ultimately compromise a primary target, and Okta itself seems to carefully limit its circle of “sub-processors.” A list of these affiliates from January 2021 shows 11 regional partners and 10 sub-processors. The latter group are well-known entities like Amazon Web Services and Salesforce. The screenshots point to Sykes Enterprises, which has a team located in Costa Rica, as a possible affiliate that may have had an employee Okta administrative account compromised.

Sykes, which is owned by the business services outsourcing company Sitel Group, said in a statement, first reported by Forbes, that it suffered an intrusion in January. 

“Following a security breach in January 2022 impacting parts of the Sykes network, we took swift action to contain the incident and to protect any potentially impacted clients,” the company said in a statement. “As a result of the investigation, along with our ongoing assessment of external threats, we are confident there is no longer a security risk.”

The Sykes statement went on to say that the company is “unable to comment on our relationship with any specific brands or the nature of the services we provide for our clients.”

On its Telegram channel, Lapsus$ posted a detailed (and frequently self-congratulatory) rebuttal to Okta’s statement.

“The potential impact to Okta customers is NOT limited, I’m pretty certain resetting passwords and [multifactor authentication] would result in complete compromise of many clients systems,” the group wrote. “If you are commited [sic] to transparency how about you hire a firm such as Mandiant and PUBLISH their report?”

For many Okta customers struggling to understand their potential exposure from the incident, though, all of this does little to clarify the full scope of the situation.

“If an Okta support engineer can reset passwords and multifactor authentication factors for users, this could present real risk to Okta customers,” Red Canary’s McCammon says. “Okta customers are trying to assess their risk and potential exposure, and the industry at large is looking at this through the lens of preparedness. If or when something like this happens to another identity provider, what should our expectations be regarding proactive notification and how should our response evolve?”

Latest news

Bandits Are Now Recruiting Young People Into Crime For As Low As N500 – Governor Radda Says

Dikko Radda, the Governor of Katsina State has revealed the bandits are recruiting young people into crime for as...

Edo: Police Re-Arrest Prisoner Who Escaped From Jail During #EndSARS Protest

The Edo State Police have recaptured Jacob Alonge, a 58-year-old fugitive who had escaped from the Benin Correctional Centre...

Xiaomi Watch S3 Review: Quirky Customization

The Xiaomi Watch S3 is an affordable smartwatch with a highly customizable look that includes swappable bezels. It can...

Sony CRE-E10 Review: Well-Rounded Hearing Aids

When Sony entered the over-the-counter hearing aid market two years ago, it did so with a pair of products:...
- Advertisement -

25 Best Mother’s Day Gifts: Ideas for the Moms in Your Life (2024)

If you buy something using links in our stories, we may earn a commission. This helps support our journalism....

As Elon Musk Abandons the $25K Tesla, This EV Costs Just $4,400

As Elon Musk steps away, yet again, from the idea of a $25,000 Tesla, let’s take this opportunity to...

Must read

Bandits Are Now Recruiting Young People Into Crime For As Low As N500 – Governor Radda Says

Dikko Radda, the Governor of Katsina State has revealed...

Edo: Police Re-Arrest Prisoner Who Escaped From Jail During #EndSARS Protest

The Edo State Police have recaptured Jacob Alonge, a...
- Advertisement -

You might also likeRELATED
Recommended to you