On March 22, 2022, the Lapsus$ threat group (aka DEV-0537), who recently gained notoriety for compromises including Microsoft, Samsung, Nvidia, and others, announced that they had compromised Identity Access Management (IAM) platform, Okta. Further, Lapsus$ claims to have gained access to client environments and sensitive information via their access to Okta. Lapsus$ representatives posted screenshots that seemed to suggest access to sensitive information, including sensitive information for Cloudflare users.
Okta initially claimed that the compromise, which occurred between 16-21 January, was limited in scope to the access of Okta support engineers. Okta indicates that while support engineers can assist users with password changes they cannot obtain those passwords, cannot create or delete users, and cannot download customer databases. Okta later indicated that 2.5% of their customers may have been impacted and had data viewed or acted upon. It isn’t clear at this point what type of data may have been seen or what type of actions may have been taken. However, Okta indicates that they have already reached out to these potentially impacted clients directly by email. Cloudflare’s investigation concluded that a compromise had not occurred within their environment Nevertheless, Cloudflare's recommendations are worth considering for organizations who use Okta as an IAM.
Cloudflare recommends the following actions:
As an additional precaution Ingalls encourages organizations who use Okta to also consider these additional recommendations:
Ingalls is dedicated to protecting your network and your information by providing defense-in-depth security through your Managed Detection & Response (MDR) service. As an added layer of defense, Ingalls now offers monitoring and support by a team of live Security Analysts in our Security Operations Center (SOC) 24 hours a day, every day of the year. ‘Round the clock, MDR provides extended coverage with continuous analysis, response and escalation so you can have the peace of mind that comes from knowing your network is being monitored in real-time even if your business hours have stopped. Please contact us for more information.