The Okta data breach just keeps getting worse

Zero-day attack
(Image credit: Shutterstock) (Image credit: Shutterstock.com)

The recent data breach suffered by Okta turned out to be a lot bigger than initially thought.

In early November, the identity and access management company reported that a threat actor managed to access files inside its customer support system. There, they stole HAR files which contained cookies and session tokens, which allowed them to bypass login credentials and multi-factor authentication (MFA) and access the victims’ endpoints.

At first, Okta believed 134 of its customers (fewer than 1%) were affected. However, it now seems that the attackers accessed additional reports and support cases with contract information for all Okta certified users. 

Reader Offer: $50 Amazon gift card with demo

Reader Offer: $50 Amazon gift card with demo
Perimeter 81's Malware Protection intercepts threats at the delivery stage to prevent known malware, polymorphic attacks, zero-day exploits, and more. Let your people use the web freely without risking data and network security.

Preferred partner (What does this mean?

Plenty of personal data

"All Okta Workforce Identity Cloud (WIC) and Customer Identity Solution (CIS) customers are impacted except customers in our FedRamp High and DoD IL4 environments (these environments use a separate support system NOT accessed by the threat actor). The Auth0/CIC support case management system was also not impacted by this incident,” Okta said in its latest report.

Stolen data includes full names, usernames, emails, company names, user types, addresses, last password change/reset, roles, phone numbers, mobile numbers, time zones, and SAML Federation IDs. The good news is that for 99.6% of the victims, only full names and email addresses were taken. Login credentials remained safe, it was added.

Many of the victims were administrators, too, with 6% not even having multi-factor authentication enabled. What’s more, the attackers stole data from "Okta certified users and some Okta Customer Identity Cloud (CIC) customer contacts.” Some data on Okta employees was taken as well.

"We also identified additional reports and support cases that the threat actor accessed, which contain contact information of all Okta certified users and some Okta Customer Identity Cloud (CIC) customer contacts, and other information,” the report states.

“Some Okta employee information was also included in these reports. This contact information does not include user credentials or sensitive personal data."

Via BleepingComputer

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Avast cybersecurity
Zapier tells customers their data may have been accessed
Illustration of a thief escaping with a white fingerprint
5 massive privacy scandals that rocked the world – and made millions of victims
Ransomware
Millions of hotel guest reservations leaked in Otelier data breach
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Google Chrome extensions targeted by hackers to steal user passwords
How to prevent cyberattacks
PowerSchool breach worse than thought, company says "all" student and teacher data accessed
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC