Okta denies it was hacked again after data appears on hacking site

Data leak
(Image credit: Shutterstock)

A hacker has shared a new database on an underground forum, claiming it contained data stolen from Okta - however the company begs to differ.

In late October 2023, cybercriminals broke into Okta systems and stole client session cookies, potentially giving them access to those companies’ networks, and opening the doors to malware and ransomware attacks. Subsequent investigation showed that all of Okta’s customers were affected. 

Now, almost half a year later, a hacker with the alias “Ddarknotevil” posted a new database on a dark web forum, claiming it contained data on 3,800 Okta customers, BleepingComputer reported.

Another Okta breach? Apparently not...

"Today, I have uploaded the Okta database for you all, This Breach is being shared in behife @IntelBroker - [Cyber <redacted>] thanks for reading and enjoy!," the thread said. "In September 2023, Okta, an IT service management company, suffered a data breach that led to the exposure of 3.8 thousand customer support users."

The database contains user IDs, full names, company names, office addresses, phone numbers, email addresses, positions/roles, and other information.

However, being asked about the database, Okta told the publication that the data didn’t belong to it, and that it was probably simply scraped from the internet.

"This is not Okta's data, and it is not associated with the October 2023 security incident," an Okta spokesperson told BleepingComputer. "We cannot determine the source of this data or its accuracy, but we noted that some fields have dates from over ten years ago. We suspect that this information may be aggregated from public information sources on the Internet."

The publication also found that cybersecurity firm KELA analyzed the data and concluded that it belonged to the National Defense Information Sharing and Analysis Center. It was apparently stolen in July last year, and published by a known leaker IntelBroker.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Ransomware
Atos now says its systems weren't hit by a ransomware attack after all
Telefonica
Telefónica says it was hit by systems breach, internal data leaked online
SearchGPT OpenAI
Hackers offer 20 million OpenAI credentials for sale, but it says there's no evidence of a breach
Security
American National Insurance Company breach data found online
Data leak
Details of over 15,000 FortiGate devices leaked online, so be on your guard
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras