OKTA

OPERATION
Identity management — "we verify you are who you say you are"
HABITAT
The single sign-on layer for thousands of enterprises
EVENT
BREACHED BY PROXYLapsus$ via a support contractor, Jan 2022 FACT
PATTERN
Late disclosure — both times, customers found it first ATTRIBUTED
DISPOSITION
~$6B market-cap drop; $60M securities class-action settlement ADJUDICATED

Here is the gatekeeper — the animal whose whole function is to check who comes through the door — observed twice failing to notice that someone had already come through, and each time being informed of the fact by its own guests.

The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers.

David Bradbury, Okta Chief Security Officer — the company's official statement on the Lapsus$ claims, posted to Okta's own blog, March 22, 2022, the day the Telegram screenshots surfaced. The same statement describes a five-day window, January 16–21, in which "an attacker had access to a support engineer's laptop."

Identity is the master key of the modern enterprise. Okta sits at the doorway and answers the one question everything else depends on: is this really you? When that animal is compromised, the compromise is not of one system but of the trust that unlocks all of them.

What the archive marks here is not merely that Okta was breached — everyone is breached — but the recurring tempo of the telling: the customer sees it first, the vendor confirms it later. Twice. Every claim carries its receipt; the defense gets equal time.

the drama timeline

ACT I — THE SPREADSHEET NAMED DOMADMINS

The breach arrives not by force but by paperwork — a file left lying around a contractor's network, named, with almost cinematic honesty, after exactly what it contained.

  1. JAN 2022

    Lapsus$ walks in through Sitel

    Lapsus$ compromises Sitel, an Okta support contractor, with stolen VPN credentials. Inside Sitel's network they find a spreadsheet named "DomAdmins-LastPass.xlsx" holding domain-admin passwords, and use it to reach Okta through the trusted contractor link. Okta learns of the compromise in January.

    The apex identity vendor was reached through the back door of a call-center subcontractor, using passwords stored in a file that announced its own contents.

  2. MAR 22 2022

    Disclosure — after the screenshots

    Okta discloses only after Lapsus$ posts screenshots to Telegram. 366 customers were potentially affected. The stock falls ~11%, ~$6B in market cap; a $60M securities class-action settlement follows in 2024.

ACT II — THE SAME MOVIE, AGAIN

A year and a half later the pattern reruns with a new entry point and the same ending: the guest notices before the host.

  1. SEP–OCT 2023

    The support system, via a personal Google account

    A threat actor accesses Okta's customer support system (Sep 28–Oct 1) through an employee's compromised personal Google account. BeyondTrust detects the attack on Oct 2 and reports it to Okta. Okta does not spot the downloads in its own logs for 14 days — the attacker used a different file-navigation path, generating a different log event ID.

  2. NOV 29 2023

    All 18,400 support users

    Okta discloses the attacker downloaded a report with the names and email addresses of all 18,400 Okta support-system users — a scope revised upward from initial statements. In both 2022 and 2023, customers found the breach before Okta told them.

    The gatekeeper's failure mode is not the lock. It is the fourteen days between the intrusion and the moment it looks up.

both sides, on the record

Breached through the trust it sells. The identity vendor was reached via a contractor and, later, a personal Google account [1] [5].

Slow, screenshot-forced disclosure. Jan-to-March in 2022, only after Telegram screenshots; a 14-day log blind spot in 2023 [2] [3].

Customers detected it first, twice. BeyondTrust told Okta in 2023; the market told it in 2022 [1].

The initial vector was a third party. The 2022 intrusion ran through Sitel's environment, not a direct compromise of Okta's core service; Okta said its service was not breached and customers need take no corrective action [5].

It published detailed post-mortems and worked with the detecting firm (BeyondTrust) and researchers on the 2023 timeline; the settlement resolved claims without an admission of the plaintiffs' characterizations [2] [4].

The 2023 exposure was contact data (names/emails of support users), not credential vaults or customer authentication secrets [1].

YOU DECIDE

Scoped to the claims. That both breaches happened, and that customers surfaced them first, is on the record. The $60M settlement is adjudicated. The "slow to disclose" characterization is the pattern the timeline shows — you can read the dates yourself.

Weigh the costly signal: the company whose product is knowing who is at the door took, by its own logs, fourteen days to notice someone was already inside.

The archive does not judge. It keeps the timestamps.

evidence locker

PRIMARY & INVESTIGATIVE

  1. Krebs on Security — "Hackers Stole Access Tokens from Okta's Support Unit" (Oct 2023) ATTRIBUTED krebsonsecurity.com/2023/10/hackers-stole-access-tokens-from-oktas-support-unit/
  2. BeyondTrust — "Okta Support Unit Breach Update & Security Implications" FACT — the detecting firm's own account. beyondtrust.com/blog/entry/okta-support-unit-breach-update
  3. Okta's costly failures — the $60M settlement case study ADJUDICATED 11th.com/blog/case-study/oktas-cybersecurity-failures/

PRESS & ANALYSIS

  1. Strac — "The 2023 Okta Support Unit Breach: Key Insights & Outcomes" ATTRIBUTED strac.io/cyber-attacks/okta-breach
  2. NetSecurity — "How Lapsus$ Breached Okta and its Customers" ATTRIBUTED netsecurity.com/how-lapsus-breached-okta-and-its-customers/
  3. Nametag — "Okta Breach Report: Timeline & Updated Impacts" ATTRIBUTED getnametag.com/newsroom/okta-breach-report-timeline-updated-impacts
The standard. Both breaches are sourced to Okta's disclosures, the detecting firm BeyondTrust, and named reporting. The "late disclosure" and "customers detected it first" characterizations are shown through the dated record, not asserted. The $60M securities settlement is stated as adjudicated (settlements resolve claims without admitting the plaintiffs' characterizations). The defense is presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.