Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Fury As Okta—The Company That Manages 100 Million Logins—Fails To Tell Customers About Breach For Months
Forbes ^ | 3/22/2022 | By Thomas Brewster

Posted on 03/22/2022 3:15:33 PM PDT by NohSpinZone

Okta, the $25 billion market cap company that handles logins for more than 100 million users, today confirmed it suffered a breach in January via a third party customer support provider. But for some customers who spoke to Forbes, the disclosure was too late and too scant with information.

Okta’s admittance came after a hacking crew called LAPSUS$, which extorts its targets after stealing their data and often leaks victims’ information in public forums, claimed it had breached the company. LAPSUS$ had previously claimed to have stolen data from major security companies including NVIDIA and Microsoft, leading both to investigate the alleged breaches. The crew posted screenshots showing access to apparent internal Okta systems in an attempt to prove the breach was real.

In a statement on Tuesday, Okta said: “In late January 2022, Okta detected an attempt to compromise the account of a third party customer support engineer working for one of our subprocessors. The matter was investigated and contained by the subprocessor. We believe the screenshots shared online are connected to this January event. Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January.” The company had not responded to further questions about the severity of the attack.

(Excerpt) Read more at forbes.com ...


TOPICS: Business/Economy; Crime/Corruption; News/Current Events; Technical
KEYWORDS: adobe; breach; databreach; experian; fedex; hackers; lapsuss; microsoft; okta; security; tmobile
I've heard of Zero Day security disclosures. I guess this is the 90 Day variety?
1 posted on 03/22/2022 3:15:33 PM PDT by NohSpinZone
[ Post Reply | Private Reply | View Replies]

To: NohSpinZone

Somebody has a data privacy mess on their hands.


2 posted on 03/22/2022 3:16:29 PM PDT by FlipWilson
[ Post Reply | Private Reply | To 1 | View Replies]

To: FlipWilson

Over 100 million somebodies do.


3 posted on 03/22/2022 3:30:21 PM PDT by Carriage Hill (A society grows great when old men plant trees, in whose shade they know they will never sit.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: NohSpinZone

I had not heard of OKTA, but they are in the . . . IDENTITY VERIFICATION business. This failure, and the slow communication and response SHOULD put them out of business.

I think at this point if I were starting up such a business I would use a proprietary OS, possibly built off of legacy OSs (e.g. DEC) and a non TCP/IP network protocol (maybe an updated, more secure version of Banyan VINES). Of course, we are then looking at $1 billion just to turn on the lights.


4 posted on 03/22/2022 3:31:40 PM PDT by Dr. Sivana (“...life is very good without Facebook and that we would live very well without Facebook."-B.LeMaire)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Dr. Sivana

Banyan Vines. Dang if that’s not the wayback machine!!!


5 posted on 03/22/2022 4:14:57 PM PDT by MercyFlush (I don't follow the science. I follow the money. )
[ Post Reply | Private Reply | To 4 | View Replies]

To: FlipWilson

This is much worse than it appears. Trust me, this is the tip of the iceberg.


6 posted on 03/22/2022 4:21:07 PM PDT by rarestia (“A nation which can prefer disgrace to danger is prepared for a master, and deserves one.” -Hamilton)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Dr. Sivana

Okta is Microsoft’s biggest identity competitor. What this represents is unconscionable. If okta lasts a year, they’ll be half their current size if not smaller.

Lapsus did more than compromise okta. They got customer data. I can’t understate how bad this is.


7 posted on 03/22/2022 4:23:13 PM PDT by rarestia (“A nation which can prefer disgrace to danger is prepared for a master, and deserves one.” -Hamilton)
[ Post Reply | Private Reply | To 4 | View Replies]

To: NohSpinZone

Go ahead ...keep using a credit card or register with stores under your own name....I have always used a pay for credit card with a name and info that IS real but not me....I put just enough on it to make a purc hase and thats it...DO NO business with a “CREDIT” card in your name...DeBIT is one thing ...and for those of you afraid to go out at night I would tell you to squirrel away cash .../s


8 posted on 03/22/2022 4:42:02 PM PDT by mythenjoseph
[ Post Reply | Private Reply | To 1 | View Replies]

To: NohSpinZone

Go ahead ...keep using a credit card or register with stores under your own name....I have always used a pay for credit card with a name and info that IS real but not me....I put just enough on it to make a purc hase and thats it...DO NO business with a “CREDIT” card in your name...DeBIT is one thing ...and for those of you afraid to go out at night I would tell you to squirrel away cash .../s


9 posted on 03/22/2022 4:42:45 PM PDT by mythenjoseph
[ Post Reply | Private Reply | To 1 | View Replies]

To: NohSpinZone

Our health care provider uses Okta to authenticate users when logging in. This is bad news!

Time to change the pw.


10 posted on 03/22/2022 5:10:20 PM PDT by ProtectOurFreedom (“Today I will do what others won't, so tomorrow I can accomplish what others can't.” ~ Jerry Rice)
[ Post Reply | Private Reply | To 1 | View Replies]

To: carriage_hill

The company I retired from last year uses OKTA.
I wonder if the Help Desk has been told that 195,000 users will have to reset their passwords and to expect a few more calls....


11 posted on 03/23/2022 1:09:50 AM PDT by minnesota_bound (Need more money to buy gas)
[ Post Reply | Private Reply | To 3 | View Replies]

To: minnesota_bound

So far, I’ve heard nothing from any sites I’m registered with, but that may change. Does OKTA list, anywhere, their client list?


12 posted on 03/23/2022 5:12:50 AM PDT by Carriage Hill (A society grows great when old men plant trees, in whose shade they know they will never sit.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: NohSpinZone

The company I work for uses Okta for all authentication. Hope it isn’t too severe. We use MFA with authorized cellphones, so I don’t know if a data breach could result in unapproved access.


13 posted on 03/23/2022 5:24:45 AM PDT by Mr170IQ
[ Post Reply | Private Reply | To 1 | View Replies]

To: minnesota_bound

Found it.
I see FedEx, Experian, Advent Health, Dignity Health, TMobile and Adobe logos at the bottom of their site’s homepage.


14 posted on 03/23/2022 6:33:07 AM PDT by Carriage Hill (A society grows great when old men plant trees, in whose shade they know they will never sit.)
[ Post Reply | Private Reply | To 12 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson