1Password says it might have been targeted following Okta breach

password manager security
(Image credit: Passwork)

Following news of a major security incident at Okta earlier this week, the attack already seems to be sending ripples across the business world. 

1Password, one of the top password manager firms around, has disclosed a cyberattack that appears to have come direct as a result of the Okta breach.

“On September 29, we detected suspicious activity on our Okta instance that we use to manage our employee-facing apps,” 1Password CTO Pedro Canahuati was cited as writing in an email. “We immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing,” Ars Technica reports.

Stealing HAR files

Canahuati added that 1Password has been investigating how the attackers managed to breach the systems, but that question has probably been answered already, by Okta itself.

Earlier this week, the identity management and authentication service provider Okta shared news of a threat actor breaching its customer support case management system, by means yet unknown. Once inside, it managed to obtain files uploaded by its customers in need, which often included authentication cookies and session tokens. These files can be used to bypass not just login credentials, but multi-factor authentication (MFA) as well, granting the attackers access to various tools and services. 

Cybersecurity experts from BeyondTrust were the first to spot the issue after one of its customers reported strange behavior on its network, following a short communication with Okta. 

1Password did not provide further details, but Ars Technica did find a report from mid-October, allegedly shared on an internal 1Password Notion workspace, which stated that the attackers obtained a HAR file one of its IT employees uploaded to Okta. The file held a record of all traffic between the 1Password employee’s browser and Okta server, including session cookies, but 1Password did not want to discuss the authenticity of the report.

The attackers apparently tried to access the IT employee’s Okta dashboard, unsuccessfully. They also updated an existing identity provider (IDP) tied to 1Password’s production Google environment and activated the IDP. Finally, they requested a report of admin users, of which all admins were notified. This notification raised red flags all around and helped the company prevent a bigger incident.

Via ArsTechnica

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An abstract image of padlocks overlaying a digital background.
BeyondTrust says hackers hit its remote support products
A hand laying out a password
Security attacks on password managers have soared
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
LastPass 2022 hack fallout continues with millions of dollars more reportedly stolen
A padlock resting on a keyboard.
Massive botnet is targeting Microsoft 365 accounts across the world
Avast cybersecurity
Zapier tells customers their data may have been accessed
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
Latest in Security
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
BadBox malware hit after infecting over 500,000 Android devices
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
Latest in News
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 could have a Motorola Razr-style full-sized cover screen – and I think it’s about time
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
Last-minute AMD RX 9070 XT stock rumors are making me hopeful for a much better launch than Nvidia’s RTX 5000 GPUs – with just one snag
eSIM
Global eSIM shipment volume surpasses half a billion units as demand keeps on growing
Samsung Galaxy Buds in white
Samsung may be working on new cheap wireless earbuds – will the Galaxy Buds FE 2 beat Sony's next value earbuds to the punch?
PS5 Pro feature
PlayStation Direct now lets you rent, yes rent, a PS5 from £11.99 a month
Google Pixel 9 Pro
Your older Pixel phone just got a performance and camera boost thanks to Google's new software update