{"id":1194749,"date":"2023-10-20T17:20:00","date_gmt":"2023-10-20T21:20:00","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1194749"},"modified":"2023-10-20T17:20:00","modified_gmt":"2023-10-20T21:20:00","slug":"hackers-stole-access-tokens-from-oktas-support-unit","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1194749","title":{"rendered":"Hackers Stole Access Tokens From Okta&#039;s Support Unit"},"content":{"rendered":"<p>An anonymous reader quotes a report from Krebs on Security: Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned. Okta says the incident affected a &#8220;very small number&#8221; of customers, however it appears the hackers responsible had access to Okta&#8217;s support platform for at least two weeks before the company fully contained the intrusion. In an advisory sent to an undisclosed number of customers on Oct. 19, Okta said it &#8220;has identified adversarial activity that leveraged access to a stolen credential to access Okta&#8217;s support case management system. The threat actor was able to view files uploaded by certain Okta customers as part of recent support cases.&#8221;<\/p>\n<p>Okta explained that when it is troubleshooting issues with customers it will often ask for a recording of a Web browser session (a.k.a. an HTTP Archive or HAR file). These are sensitive files because in this case they include the customer&#8217;s cookies and session tokens, which intruders can then use to impersonate valid users. &#8220;Okta has worked with impacted customers to investigate, and has taken measures to protect our customers, including the revocation of embedded session tokens,&#8221; their notice continued. &#8220;In general, Okta recommends sanitizing all credentials and cookies\/session tokens within a HAR file before sharing it.&#8221;<\/p>\n<p>Okta has published a blog post about this incident that includes some &#8220;indicators of compromise&#8221; that customers can use to see if they were affected. But the company stressed that &#8220;all customers who were impacted by this have been notified. If you&#8217;re an Okta customer and you have not been contacted with another message or method, there is no impact to your Okta environment or your support tickets.&#8221; The security firm BeyondTrust is among the Okta customers who was involved in the breach. &#8220;BeyondTrust Chief Technology Officer Marc Maiffret said that [Okta&#8217;s] alert came more than two weeks after his company alerted Okta to a potential problem,&#8221; reports Krebs. They have also published a blog post detailing their findings.<\/p>\n<p \/>\n<div class=\"share_submission\" style=\"position:relative\">\n<a class=\"slashpop\" href=\"http:\/\/twitter.com\/home?status=Hackers+Stole+Access+Tokens+From+Okta's+Support+Unit%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F23%2F10%2F20%2F211235%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter\"><img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/twitter_icon_large-785.png\" \/><\/a><br \/>\n<a class=\"slashpop\" href=\"http:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F23%2F10%2F20%2F211235%2Fhackers-stole-access-tokens-from-oktas-support-unit%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook\"><img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/facebook_icon_large-392.png\" \/><\/a><\/p>\n<\/div>\n<p><a href=\"https:\/\/it.slashdot.org\/story\/23\/10\/20\/211235\/hackers-stole-access-tokens-from-oktas-support-unit?utm_source=rss1.0moreanon&amp;utm_medium=feed\">Read more of this story<\/a> at Slashdot.<\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Slashdot &#8211; <a href=\"https:\/\/it.slashdot.org\/story\/23\/10\/20\/211235\/hackers-stole-access-tokens-from-oktas-support-unit?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed\" target=\"_blank\" rel=\"noopener\">Hackers Stole Access Tokens From Okta&#8217;s Support Unit<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An anonymous reader quotes a report from Krebs on Security: Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1194749\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1194750,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[101,110],"tags":[100],"class_list":["post-1194749","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-slashdot","category-unfiltered-rss","tag-slashdot"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1194749","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1194749"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1194749\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1194750"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1194749"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1194749"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1194749"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}