Okta hit by another breach, this one stealing employee data from 3rd
Full article260 words · extracted from arstechnica.com · click to collapse
“This incident does not relate to the use of Okta services and Okta services remain secure,” the representative said. “No Okta customer data is impacted by this incident.”
Rightway representatives didn’t immediately respond to an email seeking comment and additional details about the breach.
Thursday’s disclosure comes two weeks after Okta revealed that hackers compromised its customer support system and obtained credentials that allowed them to take control of customers’ internal Okta administration accounts. The attackers then used those credentials in follow-on hacks that targeted the internal administration accounts of 1Password, BeyondTrust, Cloudflare, and possibly other customers.
Okta is based in San Francisco and provides cloud identity, access management for single sign-on, multifactor authentication, and API services to thousands of organizations worldwide. The company has previously come under criticism for security breaches and its handling of them afterward. Most recently, Cloudflare called out Okta for not driving the intruders out of its network until October 18, 16 days after first learning of the compromise. Cloudflare urged Okta to act quicker in the future when learning of security breaches, providing disclosures sooner and requiring the use of hardware keys to protect internal systems and systems used by third-party support providers.
“For a critical security service provider like Okta, we believe following these best practices is table stakes,” Cloudflare researchers wrote.
The Okta representative said in Thursday’s email that when the company learned of the Rightway compromise on October 12, investigators had 27,000 records to sort through. Much of the process had to be manually done and took time to complete.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/11/okta-hit-by-another-breach-this-one-stealing-employee-data-from-3rd-party-vendor/