• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

Okta Accepts Responsibility, Explains How Recent Data Breach Occurred

April 6, 2022

Okta CEO Todd McKinnon has shared more details about a recent security breach. The hacking group Lapsus$ targeted the company with an attack in January, though the incident did not come to light until March 22, when the hackers posted screenshots that were obtained during that January event.

Okta Accepts Responsibility, Explains How Recent Data Breach Occurred

Speaking to Bloomberg Television, McKinnon accepted responsibility for the security lapse, and acknowledged that Okta should have been more forthcoming with its clients and with the public. The company looked into the incident in January, but that initial investigation did not reveal the full scope of the problem. In that regard, McKinnon stated that Okta did not realize how much information Lapsus$ had obtained until the screenshots were released.

Unfortunately, Okta is still not able to provide a full accounting of the problem, though it does seem that the event was at least partially contained. According to McKinnon, as many as 366 of the company’s 15,000+ clients may have been affected, and the companies that were hit should only need to take minimal follow-up action to re-secure their operations. In that regard, McKinnon indicated that the event should not have much technical impact on end users.

McKinnon went on to explain how Lapsus$ was able to execute its attack. He said that the breach occurred at a third-party call center, where roughly 40 employees were tasked with providing help desk support for Okta customers. The hackers used unnamed software to break into the call center, then took screenshots of computers while agents were working with those Okta clients. Okta is no longer working with that contact center, though McKinnon stressed that Okta is ultimately to blame for any security failures.

“I want to be really clear that we’re responsible,” McKinnon said. “So third-party this and third-party that. It’s our responsibility to make sure this stuff doesn’t happen.”

Okta is planning to release a report to its clients that will shed more light on the incident. The Sitel Group runs the call center that was attacked, and claims that it has closed its security gap after hiring an outside cybersecurity firm. Lapsus$ has also claimed credit for high-profile hacks of Samsung and NVIDIA.

Source: Bloomberg

Filed Under: Industry News Tagged With: call center security, cybercrime, cybersecurity, data breaches, enterprise security, hack attacks, Lapsus$, NVIDIA, Okta, Samsung, security breaches

Related News & Articles

Wirex Adds New Crypto Payment Options in India

Next iOS Update Will Let You Chat Directly with Businesses, Use New Animojis to Make it Weird

Aerendir Partners with SiFive to Make Affordable On-Device AI

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • NordPass, Yahoo! Japan, and Regula Keep Up Mobile Biometrics Momentum
  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework
  • Transatlantic Digital Traveler Identity Project Gets High-Profile Tech Partner
  • Digital Identity Tech Demo Online Event

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld