5 ms·
Okta's CEO just released a statement. And it's very tiny. Unsure what to make of this. Waiting to see LAPSUS$ response > In late January 2022, Okta detected an
by nstart 5y ago
Okta's CEO just released a statement. And it's very tiny. Unsure what to make of this. Waiting to see LAPSUS$ response
> In late January 2022, Okta detected an attempt to compromise the account of a third party customer support engineer working for one of our subprocessors. The matter was investigated and contained by the subprocessor. (1 of 2)
> We believe the screenshots shared online are connected to this January event. Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January. (2 of 2)
https://twitter.com/toddmckinnon/status/1506184721922859010 https://twitter.com/toddmckinnon/status/1506184721922859010
- hericium 5y agoOh, this absolutely looks like "an attempt". I'm sure investors are calmed by this tweet. Nothing to see here, move along.
- twistedpair 5y agoPre-market trading is already -9% (was -14.5% before that tweet).
- chillfox 5y agoSo, they covered it up in January and now wants us to believe that this is not yet another attempt at covering it up. Up until that statement I was willing to believe that they only just found out about it.
- open-source-ux 5y agoHad the same thought. A security breach in January, and only now are the details of the breach are revealed (by someone not related to Okta). In other words, Okta would never have revealed the security lapse until this leak. One can only imagine the many security breaches that are never revealed (from any company).
- tyingq 5y agoThey were kind of stuck with admitting it was active in January since most of the screenshots have a late January date showing in the bottom right hand corner.
- Phlarp 5y agoAnother possibility could be they didn't know about it in January and instead only figured it out sometime last week; at which point Todd Mckinnon sold 7600 shares of stock.
- raesene9 5y agoThis might be correct, although looks not great that they're only talking about it after the leaked screenshots. However, if LAPSUS have more, this could easily lead to them wanting to prove him wrong and release more proof of compromise. If that happens his credibility will be toast.
- parimm 5y agoThere is cloudflare PII in one of the screenshots, I wonder if Cloudflare was notified of access to their data in January. Speculation from here on. In my personal opinion,Cloudflare's actions indicate that Cloudflare was not notified of the breach until today. ```We are aware that @Okta may have been compromised. There is no evidence that Cloudflare has been compromised. Okta is merely an identity provider for Cloudflare. Thankfully, we have multiple layers of security beyond Okta, and would never consider them to be a standalone option.``` - @eastdakota - https://twitter.com/eastdakota/status/1506143353544478724 https://twitter.com/eastdakota/status/1506143353544478724
- twistedpair 5y agoThat was a pretty rapid response from CF though, are we sure they didn't know ahead of today? How long did they have to determine "no evidence" before making a public statement about it?
- ztjio 5y agoAny competent operation is continuously monitoring all available signals for signs of breach. All I read into this is that their systems have not identified any IoCs. Doesn't mean it hasn't happened, but, if you're relying on something non-automated to make these kinds of determinations, you're already pretty screwed. Forensics is definitely a thing in cases where there's reason to believe a breach happened, but, it's not the thing that will be used to decide something has happened worth investigating. Thus, it should take approximately zero actual time to conclude what was stated here.
- twistedpair 5y agoTouche... CF SIRT is an a well oiled machine [1] [1] https://blog.cloudflare.com/cloudflare-investigation-of-the-january-2022-okta-compromise/ https://blog.cloudflare.com/cloudflare-investigation-of-the-...
- throwoutway 5y ago‘“Merely” an identity provider for [us]’ is selling the understatement of the year
- failattu 5y agoYou do know this means they have broken GDPR, by not reporting a noticed breach.
- raffraffraff 5y agoDoesn't that depends on how well they separate access within the company? If they know that one of their support reps in Costa Rica was "turned", they might not have to declare anything in the EU if they can prove that the rep has zero access to EU customers. Edit: to be clear, I don't know, it's a genuine question. Does "any breach" count?
- sofixa 5y agoIt has to be a breach where EU citizens' PII was potentially accessed.
- ealexhudson 5y agoThey only have to report if there is significant risk to the individuals involved. If there are few individuals and the event was indeed contained, they have no reporting requirement.
- nokya 5y agoNotification is required only if their impact assessment concludes on a significant risk to users (which they must be able to produce to the data protection authority at any time). Otherwise, business as usual.
- hakre 5y agoOkta is a company in the United States of America, by law companies under GDPR are already in violation when transferring data to Okta and would have needed to report themselves long before the breach.
- k4ch0w 5y agoYour entire service is based on the security of your product. You owe everyone more of an explanation. The Lapsus telegram clearly shows they are using an internal Okta Admin tool to reset/disable passwords and 2FA. I'm more inclined to believe the evidence in front of my eyes than your statement. It's clear some service team at Microsoft used Okta to SSO, or a contractor that did that's why they only got 37GB of code and Bing/Cortona not Windows OS or internal tools. The group probably enumerated as much access from Okta as possible and when they had every juicy target decided to release it all for the lols. They probably have more in the works too. I'd suggest everyone today revoke any Okta SSO sessions for your apps and force a new session as a precautionary measure.
- tuwtuwtuwtuw 5y ago> It's clear some service team at Microsoft used Okta to SSO, or a contractor that did that's why they only got 37GB of code and Bing/Cortona not Windows OS or internal tools. Did i miss some news or? I know Okta and Microsoft was compromised, but is there anything which shows it was related except for the hacker group and timing?
- k4ch0w 5y agoNo, just the timing and group. Pure speculation
- memish 5y ago"third party customer support engineer working for one of our subprocessors." Holy red flags Batman. How can you be a serious security company while outsourcing such critical components?
- mv4 5y agoIt's always amusing how companies redefine their subcontractor relationships depending on the situation. The same support engineer would be presented as: 1. when marketing to customers - "our support engineer" 2. when reporting on an incident - "a third party customer support engineer working for one of our subprocessors"