Okta defends 2-week gap in response to identity token theft, says 134 customers affected (therecord.media)
from throws_lemy@lemmy.nz to cybersecurity@sh.itjust.works on 05 Nov 2023 10:40
https://lemmy.nz/post/3048233

#cybersecurity

threaded - newest

Potatos_are_not_friends@lemmy.world on 05 Nov 2023 13:52 collapse

In a new blog post on Friday, the identity management company said that from September 28, to October 17, a threat actor “gained unauthorized access to files inside Okta’s customer support system associated with 134 Okta customers.”

Oh, that doesn’t seem bad.

“The threat actor was able to use these session tokens to hijack the legitimate Okta sessions of 5 customers,” the company said, noting that three of the customers — password manager 1Password, access management firm BeyondTrust and internet security company Cloudflare — have already come forward with their own reports about what happened.

Wait, each customer each individually could be holding millions of passwords. Well yikes.