ZeroHour
Ars Technica · Securitypublished ()ingested

4 Okta customers hit by campaign that gave attackers super admin control

lowThreat actorimportance 45
Full article355 words · extracted from arstechnica.com · click to collapse

Authentication service Okta said four of its customers have been hit in a recent social-engineering campaign that allowed hackers to gain control of super administrator accounts and from there weaken or entirely remove two-factor authentication protecting accounts from unauthorized access.

The Okta super administrator accounts are assigned to users with the highest permissions inside an organization using Okta’s service. In recent weeks, Okta customers’ IT desk personnel have received calls that follow a consistent pattern of social engineering, in which attackers pose as a company insider in an attempt to trick workers into divulging passwords or doing other dangerous things. The attackers in this case call service desk personnel and attempt to convince them to reset all multi-factor authentication factors assigned to super administrators or other highly privileged users, Okta said recently.

Two-factor authentication and multi-factor authentication, usually abbreviated as 2FA and MFA, require a biometric, possession of a physical security key, or knowledge of a one-time password in addition to a normally used password to access an account.

Targeting users with the highest of permissions

When successful, the attackers used the compromised super administrator accounts to assign higher privileges to other accounts and/or reset enrolled authenticators in existing administrator accounts. In some cases, the threat actor also removed second-factor requirements from authentication policies. The threat actor also assigned a new app to access resources within the compromised organization. These “impersonation apps” were created after enrolling a new identity provider, which customers integrate into their Okta account.

“Given how powerful this is, access to create or modify an Identity Provider is limited to users with the highest permissions in an Okta organization—Super Administrator or Org Administrator,” Okta officials wrote. “It can also be delegated to a Custom Admin Role to reduce the number of Super Administrators required in large, complex environments. These recent attacks highlight why protecting access to highly privileged accounts is so essential.”

An Okta representative, citing company Chief Security Officer David Bradbury, said in an email that four customers were affected within the three-week period from July 29, when the company began tracking the campaign, through August 19. Bradbury didn’t elaborate.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/09/4-okta-customers-hit-by-campaign-that-gave-attackers-super-admin-control/