News: 1647954010

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Authentication oufit Okta investigating Lapsus$ breach report

(2022/03/22)


The Lapsus$ extortion crew has turned its attention to identity platform Okta and [1]published screenshots purportedly showing the group gaining access to the company's internals.

The incident follows the group's claim over the weekend [2]that it had made off with chunks of Microsoft's code . However, a compromise at Okta could be altogether more serious since the company's services are used by many others to manage network and application access as well as user identities.

At first glance, it appears that the group gained access to a "superuser" account as well as other internal tools. Okta has yet to confirm this is the case.

[3]

Also concerning is the fact that the screenshots appear to come from January 2022, which could mean there has been access for a while. It could also be that some sort of compromise occurred briefly, and the hackers have chosen now to show off their prowess. Okta CEO Todd McKinnon reckoned it was the latter.

We believe the screenshots shared online are connected to this January event. Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January. (2 of 2) — Todd McKinnon (@toddmckinnon) [4]March 22, 2022

Either way, if a breach occurred, the implications are grave. Oliver Pinson-Roxburgh, CEO of security outfit Bulletproof, warned: "As the gatekeeper to the networks and data of thousands of organizations, a breach at Okta would have significant consequences."

"Even before the veracity of such an incident is confirmed," he went on, "it is imperative for businesses to take proactive steps now – any delay risks the potential attack spreading."

[5]

[6]

Oz Alashe, CEO of CybSafe and chair of the UK government's DCMS Industry Expert Advisory Group on Cyber Resilience, said: "The potential attack on Okta is a striking reminder of the supply chain's cyber risks. Cybercriminals will often identify the route of least resistance. An authentication tool such as Okta provides the opportunity to breach hundreds of large enterprises in one sweep."

However, Alashe cautioned: "While Okta's investigation is ongoing, it's important the security community doesn't jump to conclusions and harass its security team at this challenging time."

[7]Biden says Russia exploring revenge cyberattacks

[8]Satellite comms networks on alert after US govt warning

[9]CISOs face 'perfect storm' of ransomware and state-supported cybercrime

[10]Devil-may-care Lapsus$ gang is not the aspirational brand infosec needs

That said, some companies were taking no chances. Cloudflare, which uses Okta as an identity provider, announced it would be resetting the Okta credentials of employees. Just in case.

We are resetting the [11]@Okta credentials of any employees who’ve changed their passwords in the last 4 months, out of abundance of caution. We’ve confirmed no compromise. Okta is one layer of security. Given they may have an issue we’re evaluating alternatives for that layer. — Matthew Prince 🌥 (@eastdakota) [12]March 22, 2022

The Register contacted Okta for comment, but the company only repeated the tweeted comments of McKinnon.

While the investigation continues, lets take a moment to review Okta's recent emissions from its social media orifice. We fervently hope that this one won't end up in the "aged badly" bucket. ®

🌟 Okta Custom Admin Roles - now available for all customers!

Learn more about our updated admin experience that goes way beyond the industry standard, offering even more flexibility 🤸‍♀️ + security 🔐

Watch how it’s done👇 + learn more 👉 [13]https://t.co/Wkh9ngt5aZ [14]pic.twitter.com/K9X4a6fpdG — Okta (@okta) [15]March 21, 2022

Get our [16]Tech Resources



[1] https://twitter.com/BillDemirkapi/status/1506107157124722690

[2] https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjoAxAZehbzVq4EFNR7TFAAAARY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://twitter.com/toddmckinnon/status/1506184722786885633?ref_src=twsrc%5Etfw

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjoAxAZehbzVq4EFNR7TFAAAARY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjoAxAZehbzVq4EFNR7TFAAAARY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/03/22/biden_cybersecurity_statement_warning/

[8] https://www.theregister.com/2022/03/21/in_brief_security/

[9] https://www.theregister.com/2022/03/18/ciso_security_storm/

[10] https://www.theregister.com/2022/03/17/lapsus-larger-companies/

[11] https://twitter.com/okta?ref_src=twsrc%5Etfw

[12] https://twitter.com/eastdakota/status/1506158901078618118?ref_src=twsrc%5Etfw

[13] https://t.co/Wkh9ngt5aZ

[14] https://t.co/K9X4a6fpdG

[15] https://twitter.com/okta/status/1505994734107512842?ref_src=twsrc%5Etfw

[16] https://whitepapers.theregister.com/



what a fucking surprise!

Anonymous Coward

Nice idea putting all your admin credentials for everyone in large businesses in one bucket in a fucking cloud.

pretty fucking obvious what would happen sooner or later.

any employees who’ve changed their passwords in the last 4 months

HereIAmJH

Shouldn't that be all of them?

Re: any employees who’ve changed their passwords in the last 4 months

Cederic

Not necessarily. There's a school of thought that forcing frequent password changes is less secure.

My employer has a 'once every 7 months' policy..

Come on Okta, talk to your customers!

Paul Eagles

The silence from Okta is deafening. Other than a single paragraph on their LinkedIn page and the tweets from the CEO I'm yet to see any communication from them.

For a company that, on their Trust Hub (https://trust.okta.com/) claims that "Trust starts with transparency" and "The Okta Trust Page is a hub for real-time information on performance, security, and compliance." I would like to think they would be more proactive. I'm certainly not seeing any "real-time information".

Different all twisty a of in maze are you, passages little.