The extortion group Lapsus$ posted screenshots suggesting it had gained access to internal systems at identity provider Okta. Okta confirmed that a third-party support engineer’s computer had been compromised in January 2022 and that up to 366 customers could have been affected.
What happened
- The screenshots were taken from the laptop of a support engineer working for a subcontractor, Sitel, over a five-day window in January.
- Okta initially downplayed the incident and was criticised for waiting two months to tell customers.
- Lapsus$ had already claimed attacks on Nvidia, Samsung, and Microsoft, often using social engineering and bought credentials.
- City of London Police arrested seven people aged 16 to 21 in connection with the group in March 2022.
Why it mattered
Because Okta controls sign-in for thousands of organisations, even a limited compromise raised alarm about identity supply chains and the speed of breach disclosure.
Lessons for organisations
Organisations should include support contractors and outsourced help desks in supplier risk assessments, limit their privileges, and insist on prompt incident notification in contracts, in line with ISO/IEC 27001 supplier controls. Treating a supplier’s security incident as your own, until proven otherwise, speeds up response.
Source: The Record
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.