{"id":3747,"date":"2022-03-24T08:52:44","date_gmt":"2022-03-24T08:52:44","guid":{"rendered":"https:\/\/www.tech-battery.com\/batteriesblog\/?p=3747"},"modified":"2022-03-24T08:52:44","modified_gmt":"2022-03-24T08:52:44","slug":"hundreds-of-companies-potentially-hit-by-okta-hack","status":"publish","type":"post","link":"https:\/\/www.tech-battery.com\/batteriesblog\/hundreds-of-companies-potentially-hit-by-okta-hack\/","title":{"rendered":"Hundreds of companies potentially hit by Okta hack"},"content":{"rendered":"\n<p>Hundreds of organisations that rely on Okta to provide access to their networks may have been affected by a cyber-attack on the company.<\/p>\n\n\n\n<p>Okta said the &#8220;worst case&#8221; was 366 of its clients had been affected and their &#8220;data may have been viewed or acted upon&#8221; &#8211; its shares fell 9% on the news.<\/p>\n\n\n\n<p>It says it has more than 15,000 clients &#8211; from big companies, including FedEx, to smaller organisations, such as Thanet District Council, in Kent.<\/p>\n\n\n\n<p>Cyber-gang Lapsus$ is behind the hack.<\/p>\n\n\n\n<p>The ransomware group &#8220;is a South American threat actor that has recently been linked to cyber-attacks on some high-profile targets&#8221;, according to Ekram Ahmed, of cyber-security company Checkpoint .<\/p>\n\n\n\n<p>&#8220;The cyber-gang is known for extortion, threatening the release of sensitive information, if demands by its victims are not made&#8221; he said.<\/p>\n\n\n\n<p>The group has previously claimed to have broken into some high-profile companies, including Microsoft.<\/p>\n\n\n\n<p>In a blog post, Microsoft said Lapsus$ had gained only limited access, after compromising a single account, but no customer code or data was involved.<\/p>\n\n\n\n<p>Concern mounted<br>\nOkta initially said the attack, in January, involved a third-party contractor, a &#8220;sub-processor&#8221;, and &#8220;the matter was investigated and contained&#8221;.<\/p>\n\n\n\n<p>&#8220;There is no evidence of ongoing malicious activity beyond the activity detected in January,&#8221; it said.<\/p>\n\n\n\n<p>But as concern mounted, Okta published a series of updated blog posts providing more detail.<\/p>\n\n\n\n<p>Chief security officer David Bradbury revealed the hackers had accessed the computer of a customer-support engineer working for the sub-processor, over a five-day period in mid-January.<\/p>\n\n\n\n<p>The attack had been &#8220;analogous to walking away from your computer at a coffee shop, whereby a stranger has &#8211; virtually, in this case &#8211; sat down at your machine and is using the mouse and keyboard&#8221;, he said.<\/p>\n\n\n\n<p>But the engineer&#8217;s computer had not provided &#8220;god-like access&#8221;, the hackers had been constrained in what they could do, Okta itself had not been breached and remained fully operational.<\/p>\n\n\n\n<p>&#8220;There are no corrective actions that need to be taken by our customers,&#8221; Mr Bradbury added.<\/p>\n\n\n\n<p>&#8216;Extreme vigilance&#8217;<br>\nThe contractor employing the engineer, Sykes, part of the Sitel Group, said it was &#8220;confident there is no longer a security risk&#8221;.<\/p>\n\n\n\n<p>But in collaboration with external cyber-security experts, it would &#8220;continue to investigate and assess potential security risks to both our infrastructure and to the brands we support around the globe&#8221;.<\/p>\n\n\n\n<p>Lapsus$ said, in online posts, it had not stolen &#8220;any databases from Okta&#8221; and was focused only on its customers.<\/p>\n\n\n\n<p>None of Okta&#8217;s clients has reported any issues &#8211; but Mr Ahmed urged &#8220;extreme vigilance and cyber-safety practices&#8221;.<\/p>\n\n\n\n<p>&#8220;The full extent of the cyber-gang&#8217;s resources should reveal itself in the coming days,&#8221; he added.<\/p>\n\n\n\n<p>Multiple applications<br>\nOne of Okta&#8217;s clients, Cloudflare, said, in a blog post, it did not believe it had been compromised.<\/p>\n\n\n\n<p>FedEx told the Reuters news agency it had &#8220;no indication that our environment has been accessed or compromised&#8221;.<\/p>\n\n\n\n<p>Thanet, which uses Okta to simplify the way staff manage and sign on to multiple applications, told BBC News the hack &#8220;has not compromised the security of the council&#8217;s data&#8221; but it &#8220;will continue to monitor the situation&#8221;.<\/p>\n\n\n\n<p>Britain&#8217;s National Cyber Security Centre said it had &#8220;not seen any evidence of impact in the UK&#8221;.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hundreds of organisations that rely on Okta to provide access to their networks may have been affected by a cyber-attack on the company. Okta said the &#8220;worst case&#8221; was 366 of its clients had been affected and their &#8220;data may have been viewed or acted upon&#8221; &#8211; its shares fell 9% on the news. It &hellip; <a href=\"https:\/\/www.tech-battery.com\/batteriesblog\/hundreds-of-companies-potentially-hit-by-okta-hack\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Hundreds of companies potentially hit by Okta hack&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3747","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/posts\/3747","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/comments?post=3747"}],"version-history":[{"count":1,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/posts\/3747\/revisions"}],"predecessor-version":[{"id":3748,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/posts\/3747\/revisions\/3748"}],"wp:attachment":[{"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/media?parent=3747"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/categories?post=3747"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/tags?post=3747"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}