All vulnerabilities
HIGHOpSec

OPSEC-OKTA-2023

Identity · Okta

Summary

Between September 28 and October 17, 2023, an attacker used stolen credentials to access Okta's customer support case-management system. The credentials belonged to a service account that an employee had saved into their personal Google account after signing into a personal Chrome profile on an Okta-managed laptop. The attacker downloaded customer-uploaded HTTP Archive (HAR) files, some of which contained valid session tokens usable for session hijacking. The breach affected 134 customers, with confirmed session hijacking at five, including BeyondTrust, Cloudflare, and 1Password. Okta disabled the service account and blocked personal Google sign-ins on managed devices.

References

Related vulnerabilities

All OpSec →