Sicherheit

Okta confirms January breach after hackers publish screenshots of its internal network

Kommentar

Image Credits: Tiffany Hagler-Geard / Bloomberg (opens in a new window) / Getty Images

Identity giant Okta has confirmed a January security incident after hackers posted screenshots overnight apparently showing access to the company’s internal systems.

The Lapsus$ hacking group published several screenshots to its Telegram channel purporting to show internal Okta applications, Jira bug ticketing system, and the company’s Slack on January 21. Lapsus$ claimed it did not steal data from Okta, and that its focus was on targeting Okta customers.

Okta is used by thousands of organizations and governments worldwide as a single sign-on provider, allowing employees to securely access a company’s internal systems, such as email accounts, calendars, applications and more.

Okta chief executive Todd McKinnon confirmed the breach in a tweet thread overnight on March 22: “In late January 2022, Okta detected an attempt to compromise the account of a third party customer support engineer working for one of our subprocessors. The matter was investigated and contained by the subprocessor.”

“We believe the screenshots shared online are connected to this January event. Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January.”

Okta has not yet named the subprocessor, and has not yet responded to TechCrunch’s questions about the breach.

In an updated statement, Okta’s chief security officer David Bradbury said the compromise was with one of Okta’s third-party providers over a five-day window between January 16-21, 2022. Forbes is reporting that the company in question is Sykes, a company acquired by Sitel Group in July 2021. In a brief statement, Sitel said it was “confident there is no longer a security risk,” but declined to comment on its relationship with its customers, and did not immediately answer our questions.

Security researcher Bill Demirkapi said that the screenshots contain several artifacts that suggest the hackers may have used Sykes’ remote access tools and VPN to gain access to Okta’s network.

Lapsus$ has targeted several big-name companies in recent weeks, including Nvidia and Samsung. Just this week Microsoft said it was investigating a possible security breach. According to Wired, the group focused on Portuguese-language targets, including Portuguese media giant Impresa, and the South American telecom companies Claro and Embratel.


If you know more about the Okta breach or work at the company, get in touch with the security desk on Signal at +1 646-755-8849 or [email protected] by email.

More TechCrunch

23andMe, the personal genomics company, went public in early 2021 via a merger with a blank check company that valued it at $3.5 billion. Then its fortunes began to sink.…

23andMe sees independent board directors quit en masse

California Governor Gavin Newsom said there are 38 bills on his desk that would create laws around artificial intelligence on Tuesday, but one looms larger than all of them: SB…

Governor Newsom on California AI bill SB 1047: ‘I can’t solve for everything’

Amazon has named long-time executive Samir Kumar as the new head of its India consumer business, a month after its domestic business’ head resigned.

Amazon taps long-time exec to lead India business as competition intensifies

Al Gore has enjoyed a very successful career, including as a U.S. senator, U.S. Vice President, U.S. presidential nominee, and even Nobel Peace Prize winner in 2007 for “informing the…

Al Gore roasts corporations and politicians, comparing their climate crisis promises to ‘New Year’s resolutions’

On Tuesday, California Governor Gavin Newsom signed some of America’s toughest laws yet regulating the artificial intelligence sector. Three of these laws crack down on AI deepfakes that could influence…

California’s 5 new AI laws crack down on election deepfakes and actor clones

NASA wants to establish a permanent human presence on the moon, but right now, astronauts have to be in direct line of sight with Earth to phone home.  The space…

Intuitive Machines lands $4.8B NASA contract to build Earth-moon communications infrastructure

JPMorgan Chase is in talks to take over the Apple Card business from Goldman Sachs, The Wall Street Journal reports. Goldman has issued credit for the Apple Card since its…

JPMorgan could take over Goldman’s Apple Card business

Featured Article

Why United chose SpaceX’s Starlink to power its free Wi-Fi

Late last week, United Airlines announced that it signed an agreement with Elon Musk’s SpaceX to bring its Starlink internet service to its entire fleet and — for the first time — offer free Wi-Fi to all passengers. To dig a bit deeper into why United went with Starlink, what…

Why United chose SpaceX’s Starlink to power its free Wi-Fi

Every month, 400,000 free members upgrade to paid memberships, the company says. According to Patreon, Autopilot improved the rate of free-to-paid membership upgrades by an average of 19% in testing.

Patreon launches features to automate away creators’ administrative workload and help them make more money

Investment powerhouse BlackRock is set to launch a massive AI-focused fund, exceeding $30 billion, in collaboration with Microsoft and the Abu Dhabi-backed investment outfit MGX, the FT reported today. According…

BlackRock and Microsoft are reportedly planning a $30B AI-focused megafund

Neuralink, the Elon Musk-owned brain-computer interface company, on Tuesday received “breakthrough device” clearance from the FDA. But this does not mean the outfit has developed a cure for blindness, no…

Neuralink’s ‘breakthrough device’ clearance from FDA does not mean it has cured blindness

Discord will now offer audio and video calls that even the company won’t be able to listen in on.

Discord launches end-to-end encrypted voice and video chats

Users will be able to download their data or migrate their account to another Mastodon instance, if they choose.

Mozilla exits the fediverse and will shutter its Mastodon server in December

Mistral AI launched a new free tier to let developers fine-tune and build test apps with the startup’s AI models, the company announced in a blog post Tuesday. The startup…

Mistral launches a free tier for developers to test its AI models

Ursa Major, a startup that produces rocket motors through 3D printing, received a $12.5 million grant to develop new solid-fuel rocket engines.

Ursa Major nabs $12.5M from US Navy, DoD for 3D-printed rocket motors

The Spectacles 5 are designed specifically for developers.

Snap’s extremely large Spectacles bring impressive AR to developers at $99 a month

AWS’ weird AI-powered keyboard experiment, DeepComposer, is no more. In a blog post today, the company announced it’s shutting down the 5-year-old DeepComposer, a physical MIDI piano and AWS service…

AWS shuts down DeepComposer, its MIDI keyboard for AI music

Snap, Snapchat’s parent company, is expanding its suite of AI tools for creators. At this year’s Snap Partner Summit in Santa Monica, California, Snap announced a new feature, Easy Lens,…

Snap’s new AI feature lets you create Snapchat Lenses by simply describing them

At Tuesday’s annual Snap Partner Summit, the Snapchat maker unveiled new tools for creators designed to bring its app more in line with its competitors, like TikTok and Instagram. The…

Snapchat launches video comments and tools for creators seeking brand deals

At its annual Snap Partner Summit on Tuesday, Snapchat announced that it’s introducing a new AI video-generation tool for creators. The tool will allow select creators to generate AI videos…

Snap is introducing an AI video-generation tool for creators

Snapchat is rolling out a simplified version of the app to some users, the company announced on Tuesday during its Snap Partner Summit, as part of a test to make…

Snapchat tests ‘simple’ version of the app without Snap Map or Stories tab

At its annual Snap Partner Summit on Tuesday, the Snapchat maker announced a series of new AI features coming to its app. Most notably, the app’s My AI chatbot is…

Snapchat’s My AI chatbot is getting new Google Lens-like features 

Just a day after third-party app stores were officially allowed on the iPad in the European Union, Epic Games announced on X that the Epic Games Store can now be…

Epic Games Store — and Fortnite — now available on iPad in the EU

Tuesday’s announcement follows IBM’s $4.3 billion acquisition of Apptio in 2023, another company in the FinOps space.

IBM acquires Kubernetes cost optimization startup Kubecost

Google says that it plans to roll out changes to Google Search to make clearer which images in results were AI generated — or edited by AI tools. In the…

Google will begin flagging AI-generated images in Search later this year

With iOS 18, users can replace the default camera app on the lock screen with a third-party app. Halide and Obscura — two popular camera apps designed as alternatives to…

iOS 18 lets you replace Apple’s camera app with Halide or Obscura on the lock screen: Here’s how

Featured Article

A comprehensive list of 2024 tech layoffs

A complete list of all the known layoffs in tech, from Big Tech to startups, broken down by month throughout 2024.

A comprehensive list of 2024 tech layoffs

A joint pilot by Apian, Alphabet’s drone company Wing, and the U.K.’s NHS will see drones used to fly urgent blood samples between two hospitals in London. 

Londoners will soon see drones ferrying blood between hospitals

We’re incredibly excited to announce the final agenda for our dedicated Fintech Stage at TechCrunch Disrupt 2024. It joins Space, SaaS, AI and Builders as the other industry-focused stages —…

Announcing the final agenda for the Fintech Stage at TechCrunch Disrupt 2024

Are we at peak social media yet? It’s an interesting question to ponder after the launch of an iOS app offering a social media experience just for one. At a…

SocialAI offers a Twitter-like diary where AI bots respond to your posts