Okta data breach dilemma dwarfs earlier estimates
- Reference: 1701277265
- News link: https://www.theregister.co.uk/2023/11/29/okta_misjudged_breach_scale/
- Source link:
Chief security officer David Bradbury originally said earlier this month that according to the company's root cause analysis, the files of just 134 Okta customers – less than 1 percent of the total – were accessed by attackers.
An update published this morning instead revealed that data related to every single Okta customer support system user was accessed.
[1]
For 99.6 percent of customers, the only data accessed was the full name and email address, due too many of the data fields the attackers scanned for being blank on Okta's records. The data types included in the reports run by the attackers are below. User credentials and sensitive personal data were not included.
Created Date
Last Login
Full Name
Username
Company Name
User Type
Address
Date of Last Password Change or Reset
Role: Name
Role: Description
Phone
Mobile
Time Zone
SAML Federation ID
"While we do not have direct knowledge or evidence that this information is being actively exploited, there is a possibility that the threat actor may use this information to target Okta customers via phishing or social engineering attacks," [2]said Bradbury.
"Okta customers sign in to Okta's customer support system with the same accounts they use in their own Okta org. Many users of the customer support system are Okta administrators. It is critical that these users have multi-factor authentication (MFA) enrolled to protect not only the customer support system, but also to secure access to their Okta admin console(s).
[3]
[4]
"Given that names and email addresses were downloaded, we assess that there is an increased risk of phishing and social engineering attacks directed at these users. While 94 percent of Okta customers already require MFA for their administrators, we recommend ALL Okta customers employ MFA and consider the use of phishing-resistant authenticators to further enhance their security."
As for how the blunder materialized, Okta said it ran additional analyses of its [5]earlier findings , involving the manual recreation of the reports generated by the attacker, and found a file much larger than the one generated in its original investigation.
[6]
The larger file was attributed to the attacker running an unfiltered view of the report and when Okta did the same, it generated a file much closer in size to the attacker's.
In the process of figuring out how the mistake came to be, it also identified additional reports accessed by the attackers, including employee information and the contact details of all Okta certified users and some Okta Customer Identity Cloud (CIC) customers.
"We are working with a third-party digital forensics firm to validate our findings and we will be sharing the report with customers upon completion," Bradbury said.
[7]
The incident has attracted broad scrutiny from infosec watchers, with some [8]questioning whether this miscalculation and associated communications have done more damage than the incident itself.
It's been a torrid few months for Okta, marred by numerous security snafus. At the end of August, it [9]disclosed a case involving attackers attributed to the [10]Scattered Spider group – thought to be an AlphV/BlackCat ransomware affiliate – phishing Okta customers en masse to gain super admin access to Okta tenants.
[11]Japan's space agency suffers cyber attack, points finger at Active Directory
[12]Plex gives fans a privacy complex after sharing viewing habits with friends by default
[13]Industry piles in on North Korea for sustained rampage on software supply chains
[14]Attack on direct debit provider London & Zurich leaves customers with 6-figure backlogs
At least four customers were known to be affected at the time and it was later revealed that two of these included [15]MGM Resorts and [16]Caesars Entertainment , which together were forced to pay in excess of $115 million to clean up the mess.
Caesars reportedly paid a $15 million ransom while MGM took a $100 million hit to restore itself without bulking out the attackers' wallets.
Then in October, Okta's customer support system breach was [17]announced , an incident in which attackers made off with HAR files to replicate genuine customer sessions.
1Password said it was a victim of the breach [18]days later , but spotted it before any nastiness could take place. Attackers were reportedly still in their reconnaissance phase when they got booted out.
On November 2, the data of just shy of 5,000 current and former Okta employees was [19]exposed to attackers , although this attack was carried out on a third-party provider, Rightway Healthcare, so there's not much Okta could have done to intervene.
Regardless, it has been a less-than-ideal period for the identity vendor that just last year had to contend with being [20]breached by a band of teenagers , as well as an earlier encounter with Scattered Spider. The group was also blamed for the 2022 " [21]Oktapus " phishing campaign that claimed a handful of high-profile scalps like Twilio and Cloudflare.
Okta is due to release its quarterly earnings later today, a little more than a month after the October breach caused its stock price to plummet. ®
Get our [22]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZWfClo4sRQlouh2L3tfE@QAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://sec.okta.com/harfiles
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWfClo4sRQlouh2L3tfE@QAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWfClo4sRQlouh2L3tfE@QAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/11/06/security_in_brief/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWfClo4sRQlouh2L3tfE@QAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWfClo4sRQlouh2L3tfE@QAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://twitter.com/UK_Daniel_Card/status/1729798226105008278
[9] https://www.theregister.com/2023/09/01/okta_scattered_spider/
[10] https://www.theregister.com/2023/11/17/fbi_scattered_spider_action/
[11] https://www.theregister.com/2023/11/29/jaxa_cyberattack/
[12] https://www.theregister.com/2023/11/28/plex_privacy/
[13] https://www.theregister.com/2023/11/23/north_korea_attacks/
[14] https://www.theregister.com/2023/11/23/ransomware_attack_at_london_zurich/
[15] https://www.theregister.com/2023/10/06/mgm_resorts_cyberattack_cost/
[16] https://www.theregister.com/2023/10/12/caesars_breach_notification/
[17] https://www.theregister.com/2023/10/22/in_brief_security/
[18] https://www.theregister.com/2023/10/24/1password_confirms_all_logins_are/
[19] https://www.theregister.com/2023/11/02/okta_staff_personal_data/
[20] https://www.theregister.com/2022/06/22/okta_lapsus_zero_trust_explanation/
[21] https://www.theregister.com/2022/08/25/twilio_cloudflare_oktapus_phishing/
[22] https://whitepapers.theregister.com/
These days the internet and our privacy is cloudy ... A Cloudy world is not a problem (you're right, it's only a matter of time) until we see a thunderstorm with a few inches of rain rolling towards us ...
Seems like it's time to go back to the main questions of the Watergate era. What did Okta know, and when did they know it? It seems difficult to believe that they're only just now figuring all this out, and more likely they are sitting on plenty more, which they'll only reveal if they're somehow forced to. Wouldn't surprise me in the least if this latest disclosure was intended to head off any lawsuits from affected customers.
Anyway, that all said, since the place I worked at recently used Okta, it's just one more reason why I'm glad I'm not there anymore.
Oktagone
A previous employer went full-Okta. Laptops, IT systems, mail, messaging, facilities, all cloud systems, ... everything. An Okta failure would be a disaster recovery scenario with a few people manually re-adding standard accounts, one host, one user at a time. This was weeks after a couple of minor Okta outages and an Okta hack that compromised systems.
Shareholders have no idea just how fragile their cloud investments are.
Grandma’s on the Roof ..
[1]What to Do When Grandma’s on the Roof
[1] https://thenamiracleoccurs.wordpress.com/2012/07/17/what-to-do-when-grandmas-on-the-roof/
It can only be a matter of time before one of the major cloud providers has to announce an extensive compromise of customer accounts…