Article Details
Scrape Timestamp (UTC): 2023-11-02 14:13:08.392
Original Article Text
Click to Toggle View
Okta data breach exposed personal information of employees. Okta is warning nearly 5,000 employees that the company was impacted by a data breach that exposed personal information. Okta is a San Fransisco-based cloud identity and access management solutions provider whose Single Sign-On (SSO), multi-factor authentication (MFA), and API access management services are used by thousands of organizations worldwide. The data breach notification warns of a security incident that impacted Rightway Healthcare, which provides healthcare coverage for Okta employees and their families. On September 23, 2023, Rightway suffered a network breach, resulting in cybercriminals accessing an eligibility census file maintained for insurance provision and benefit plans for eligible individuals. The file contained the following information on current and former Okta employees and their dependents: Okta learned about the breach on October 12, 2023, when Rightway disclosed the attack, and immediately launched an investigation to determine the extent of the compromise. According to Okta's report to the Office of the Maine Attorney General, the breach impacted a total of 4,961 employees. Apart from the exposure of health information, the leak of employees' full names could be helpful to cybercriminals in deriving corporate email addresses and engaging in targeted brute-forcing to hijack valuable accounts within the company. The notice highlights twice that Okta has no evidence the personal information of those people has been misused. However, the firm encloses instructions on enrolling for two-year credit monitoring, identity theft protection, and fraud protection services through Experian. Okta's recent mishaps Okta has suffered a series of breaches over the past two years due to social engineering attacks or credential theft. On October 20, 2023, Okta warned that attackers accessed files containing cookies and session tokens uploaded by customers to its support management system after breaching it using stolen credentials. This exposure impacted customers of Okta, including BeyondTrust, Cloudflare, the 1Password password manager, and possibly many more. In December 2022, Okta admitted that hackers accessed confidential information and source code stored within private GitHub repositories. A similar hack was claimed in March 2022 by the notorious Lapsus$ threat group, this time involving customer data too, which the software vendor later admitted is real, saying it impacted 2.5% of its customers. Although the recent incident did not impact any customers, it affects a noteworthy number of individuals and elevates the overall security risk for the company.
Daily Brief Summary
San Francisco-based Okta has revealed that almost 5,000 of its employees have had their personal data exposed due to a recent data breach.
The breach impacted Rightway Healthcare, a provider that offers healthcare coverage to Okta's employees and their families.
The cybercriminals accessed a file which was maintained for the insurance provision and benefit plans of eligible individuals. This file included details on current and former employees of Okta and their dependants.
Okta began investigations into the extent of the compromise after the breach was disclosed by Rightway on October 12, 2023.
Despite the exposure, Okta stated that there has been no evidence of misuse of the leaked personal information.
Affected individuals are being offered two-year credit monitoring, identity theft protection and fraud protection services through Experian as a precaution.
This incident is the latest in a series of breaches experienced by Okta in recent years, but unlike past incidents, this breach did not impact any Okta customers.
The leak of employees' full names could potentially aid cybercriminals in deriving corporate email addresses for further targeted attacks.