OKTA▊
- OPERATION
- Identity management — "we verify you are who you say you are"
- HABITAT
- The single sign-on layer for thousands of enterprises
- EVENT
- BREACHED BY PROXY — Lapsus$ via a support contractor, Jan 2022 FACT
- PATTERN
- Late disclosure — both times, customers found it first ATTRIBUTED
- DISPOSITION
- ~$6B market-cap drop; $60M securities class-action settlement ADJUDICATED
Here is the gatekeeper — the animal whose whole function is to check who comes through the door — observed twice failing to notice that someone had already come through, and each time being informed of the fact by its own guests.
The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers.
David Bradbury, Okta Chief Security Officer — the company's official statement on the Lapsus$ claims, posted to Okta's own blog, March 22, 2022, the day the Telegram screenshots surfaced. The same statement describes a five-day window, January 16–21, in which "an attacker had access to a support engineer's laptop."
Identity is the master key of the modern enterprise. Okta sits at the doorway and answers the one question everything else depends on: is this really you? When that animal is compromised, the compromise is not of one system but of the trust that unlocks all of them.
What the archive marks here is not merely that Okta was breached — everyone is breached — but the recurring tempo of the telling: the customer sees it first, the vendor confirms it later. Twice. Every claim carries its receipt; the defense gets equal time.
the drama timeline
ACT I — THE SPREADSHEET NAMED DOMADMINS
The breach arrives not by force but by paperwork — a file left lying around a contractor's network, named, with almost cinematic honesty, after exactly what it contained.
-
JAN 2022
Lapsus$ walks in through Sitel
Lapsus$ compromises Sitel, an Okta support contractor, with stolen VPN credentials. Inside Sitel's network they find a spreadsheet named "DomAdmins-LastPass.xlsx" holding domain-admin passwords, and use it to reach Okta through the trusted contractor link. Okta learns of the compromise in January.
The apex identity vendor was reached through the back door of a call-center subcontractor, using passwords stored in a file that announced its own contents.
-
MAR 22 2022
Disclosure — after the screenshots
Okta discloses only after Lapsus$ posts screenshots to Telegram. 366 customers were potentially affected. The stock falls ~11%, ~$6B in market cap; a $60M securities class-action settlement follows in 2024.
ACT II — THE SAME MOVIE, AGAIN
A year and a half later the pattern reruns with a new entry point and the same ending: the guest notices before the host.
-
SEP–OCT 2023
The support system, via a personal Google account
A threat actor accesses Okta's customer support system (Sep 28–Oct 1) through an employee's compromised personal Google account. BeyondTrust detects the attack on Oct 2 and reports it to Okta. Okta does not spot the downloads in its own logs for 14 days — the attacker used a different file-navigation path, generating a different log event ID.
-
NOV 29 2023
All 18,400 support users
Okta discloses the attacker downloaded a report with the names and email addresses of all 18,400 Okta support-system users — a scope revised upward from initial statements. In both 2022 and 2023, customers found the breach before Okta told them.
The gatekeeper's failure mode is not the lock. It is the fourteen days between the intrusion and the moment it looks up.
both sides, on the record
Breached through the trust it sells. The identity vendor was reached via a contractor and, later, a personal Google account [1] [5].
Slow, screenshot-forced disclosure. Jan-to-March in 2022, only after Telegram screenshots; a 14-day log blind spot in 2023 [2] [3].
Customers detected it first, twice. BeyondTrust told Okta in 2023; the market told it in 2022 [1].
The initial vector was a third party. The 2022 intrusion ran through Sitel's environment, not a direct compromise of Okta's core service; Okta said its service was not breached and customers need take no corrective action [5].
It published detailed post-mortems and worked with the detecting firm (BeyondTrust) and researchers on the 2023 timeline; the settlement resolved claims without an admission of the plaintiffs' characterizations [2] [4].
The 2023 exposure was contact data (names/emails of support users), not credential vaults or customer authentication secrets [1].
YOU DECIDE
Scoped to the claims. That both breaches happened, and that customers surfaced them first, is on the record. The $60M settlement is adjudicated. The "slow to disclose" characterization is the pattern the timeline shows — you can read the dates yourself.
Weigh the costly signal: the company whose product is knowing who is at the door took, by its own logs, fourteen days to notice someone was already inside.
The archive does not judge. It keeps the timestamps.
evidence locker
PRIMARY & INVESTIGATIVE
PRESS & ANALYSIS
The standard. Both breaches are sourced to Okta's disclosures, the detecting firm BeyondTrust, and named reporting. The "late disclosure" and "customers detected it first" characterizations are shown through the dated record, not asserted. The $60M securities settlement is stated as adjudicated (settlements resolve claims without admitting the plaintiffs' characterizations). The defense is presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.