• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

Okta Becomes Latest Target of High-Profile Hacking Group

March 22, 2022

A prominent hacking group is creating more headaches for some of the world’s biggest companies. Lapsus$ has previously claimed responsibility for high-profile of hacks of Samsung and NVIDIA, and has now posted screenshots that indicate that it has gained access to Okta’s backend systems.

Okta Becomes Latest Target of High-Profile Hacking Group

If true, the hack could have a massive ripple effect across multiple industries. Lapsus$ has posted screenshots that were purportedly pulled from Okta’s internal Slack channels on its Telegram account, and claims to have had Superuser/Admin access to Okta’s systems for the past two months. However, the group has stated that Okta is not its primary target, and that it is instead looking to go after some of the more than 15,000 organizations that rely on Okta for cybersecurity. In that regard, Okta’s client roster includes corporate giants like FedEx and T-Mobile, in addition to government agencies like the FCC.

For its part, Okta is currently investigating the Lapsus$ claim, though the company seems to believe that Lapsus$ has overstated its case and its level of access. An Okta spokesperson acknowledged that there was a cybersecurity incident in January, in which a hacker attempted to compromise the account of a third party support engineer working with an Okta subprocessor. The spokesperson went on to state that the problem was identified and contained at that time, and that there is no evidence of someone with unapproved access.

That is obviously at odds with the Lapsus$ post, and it is not yet clear whose version of events is correct. Okta believes that the screenshots were pulled from that January attack. Lapsus$, on the other hand, says that Okta is still dealing with an ongoing concern, and that it has not managed to purge all of the malicious actors from its systems.

Either way, Okta’s customers are advised to be extra vigilant at the current moment. Several independent cybersecurity experts have indicated that Lapsus$ has provided enough evidence to lend credibility to its claims, so anyone using Okta for authentication should be on high alert for any signs of malfeasance, at least until the situation is fully investigated.

Lapsus$ was able to obtain key source code in the Samsung and NVIDIA cases, and in the latter instance threatened to release that code unless NVIDIA eases its cryptocurrency mining restrictions. It seems likely that the Okta attack is also financially motivated, although it is not yet clear if the group has made any demands of the security provider.

Sources: The Verge and Reuters

Filed Under: Industry News Tagged With: authentication, cybersecurity, digital security, enterprise security, hack attacks, hacking groups, hacks, Lapsus$, Okta, security breaches

Related News & Articles

NEXT Biometrics Announces New Partnership with APAC Card Maker

Jumio Details Benefits of Document-Based Identity Proofing

CLEAR Launches Digital Vaccine Card

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • NordPass, Yahoo! Japan, and Regula Keep Up Mobile Biometrics Momentum
  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework
  • Transatlantic Digital Traveler Identity Project Gets High-Profile Tech Partner
  • Digital Identity Tech Demo Online Event

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld