Sitel blames Okta breach on ‘legacy’ network from acquisition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-34484 | Privilege Escalation in Microsoft Windows User Profile Service (CWE-269) CVE-2021-34484 is a privilege escalation flaw in the Microsoft Windows User Profile Service in which the service improperly handles user profiles, allowing an attacker who can already run code on a local machine to gain elevated privileges. The flaw is triggered by local execution, meaning an attacker must first obtain a foothold on the target system — for example via malware, a compromised account, or a chained remote code execution bug — and then exploit the User Profile Service to elevate. By escalating privileges, an attacker can typically gain SYSTEM-level access, take full control of the host, disable security tooling, and move laterally across a network, which makes this bug a common step in ransomware and broader intrusion chains. All Microsoft Windows deployments are in scope per CISA, though only unpatched systems are practically at risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-03-31 with a required action to apply vendor updates, and EPSS assigns a 21.8% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk. Do: Apply Microsoft's security updates for the User Profile Service privilege escalation per vendor instructions, as required by CISA's KEV catalog entry. Because this is a local privilege escalation often chained with initial-access or malware infections, prioritize hosts where untrusted users can execute code — workstations, RDP/session hosts, and VDI — and confirm the applicable August 2021 (or later) cumulative update is installed. Use EDR telemetry and Windows Event Logs (User Profile Service activity) to check for signs of prior exploitation on systems that were unpatched since before the fix was released. | 7.8 | 22% | KEV |
| masshundreds of millions of Windows devices and installations worldwide; effectively every unpatched Windows endpoint and server |
Full article659 words · extracted from therecord.media · click to collapse
Sitel, the company at the center of a wide-ranging data breach affecting popular access management provider Okta, cited a legacy network from a recent acquisition as the cause of the security incident. The company has faced significant backlash since Okta revealed that it notified them of the breach in January and had to wait until March before a full report on the incident was compiled and sent. Before the report was released and customers were informed, extortion group Lapsus$ released data from Okta that was obtained through the compromise of Sitel’s systems. In a statement this week, Sitel said they traced the breach back to a legacy network of Sykes Enterprises, a company Sitel acquired in August 2021. Sitel said it was releasing the statement because they feel some facts “have been portrayed inaccurately in recent media coverage.” “Late on January 20, 2022, Sitel Group was made aware of a security incident affecting a portion of the legacy Sykes network only. Following this security incident, Sitel Group took swift action to contain the attack and to notify and protect any potentially impacted clients who were serviced by the legacy organization,” the company said. “The next morning, on January 21, 2022, Sitel Group issued client-facing communications to notify customers who were possibly impacted by this incident.” The Record reached out to Sitel following their disclosure, asking how many other clients besides Okta were impacted by the breach. On its website, the company says it works in at least 40 countries and has more than 700 deals with customer brands. Rebecca Sanders, director of global communications for Sitel, said in an email that the company had “nothing further to add at this time.” Security researcher Bill Demirkapi released a copy of a report that he said was compiled by cybersecurity firm Mandiant about the breach, highlighting the step-by-step process Lapsus$ hackers used to gain access to Sitel’s systems. New documents for the Okta breach: I have obtained copies of the Mandiant report detailing the embarrassing Sitel/SYKES breach timeline and the methodology of the LAPSUS$ group. 1/N https://t.co/z05uQYclg9 pic.twitter.com/e0T4EdWPxT According to the documents, the hackers exploited CVE-2021-34484 before using off-the-shelf tools from GitHub to bypass the company’s FireEye endpoint agent. From there, the hackers downloaded popular credential dumping utility Mimikatz and created backdoor users into Sitel's environment after gaining access to an Excel document titled "DomAdmins-LastPass.xlsx." Sitel denied that the spreadsheet had anything to do with the breach. “Several media articles have falsely alleged that a spreadsheet was disclosed that contained compromised passwords and contributed to the security incident. This ‘spreadsheet’ identified in recent news articles simply listed account names from legacy Sykes but did not contain any passwords,” the company said. “The only reference to passwords in the spreadsheet was the date in which passwords were changed per listed account; no passwords were included in this spreadsheet. Such information is inaccurate and misleading and did not contribute to the incident.” They went on to say that they are working with law enforcement on the issue and will not release any more information about the situation. Sitel also denied that it had left its clients in the dark, arguing that it was in “ongoing and regular communications with the customers who may have been impacted” by the incident. Emsisoft threat analyst Brett Callow said the identity of the other clients and the extent to which they may have been impacted is not known at this point, but noted that “Sitel’s statement would appear to imply that Okta was not the only one of the companies’ clients to be impacted.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/sitel-blames-okta-breach-on-legacy-network-from-acquisition