Okta is a company whose entire value proposition is identity security. Thousands of organizations use Okta to manage their employees' single sign-on - the system that lets users log in once and access dozens of applications. When Okta is compromised, the downstream blast radius extends to every company and user that trusts Okta as their authentication provider. Okta suffered two significant security incidents in two years: a 2022 breach by Lapsus$ that gave attackers access to Okta's support tools, and a 2023 breach via a stolen HAR (HTTP Archive) file that gave attackers access to all Okta customer support tickets. The serial nature of the incidents raised serious questions about the company's security culture and its transparency with customers.

The 2022 breach by Lapsus$ was discovered by the attackers themselves, who posted screenshots to their Telegram channel on March 22, 2022. The screenshots showed what appeared to be Okta's internal support system with access to customer data. Okta's initial response suggested the incident was limited and had been contained months earlier - a framing that Lapsus$ immediately disputed by posting more screenshots. The resulting public confusion about the timeline, scope, and Okta's disclosure practices became as damaging as the breach itself.

The Lapsus$ Breach (January-March 2022)

Lapsus$ gained access to an account belonging to a support engineer at Sitel Group, a company that provided contract support services to Okta. Sitel's systems had access to Okta's internal customer support tools - a "superuser" dashboard that allowed support staff to view and modify customer account configurations. This access was necessary for support work but represented a significant third-party supply chain risk.

The compromise of the Sitel contractor account occurred in January 2022. Lapsus$ had access to Okta's customer support tools for approximately five days. During that window, they could view customer information and potentially impersonate support staff. However, the access was to the support tool, not to Okta's core authentication infrastructure - customer passwords and authentication tokens were not directly accessible through the support interface.

Okta was notified by Sitel of the incident in January 2022 but apparently did not immediately grasp the significance. When Lapsus$ posted screenshots on March 22, Okta's first public statement on March 22 said "In January 2022, Okta detected an attempt to compromise the account of a third party customer support engineer working for one of our subprocessors." This minimized framing - "attempt to compromise" rather than "successful compromise" - was contradicted by Lapsus$'s screenshots showing live system access. Okta's CEO Todd McKinnon later acknowledged that the company's communication had been inadequate.

[TECHNICAL NOTE]
The Okta 2022 Lapsus$ breach illustrated the supply chain and third-party contractor risk problem in identity management. Okta outsourced customer support to Sitel Group, giving Sitel employees access to Okta's internal tooling. Sitel employees with this access became an attack surface for Okta that Okta did not directly control. The Lapsus$ methodology in this case was likely the same push-bombing MFA fatigue or credential theft approach used in other Lapsus$ attacks: compromise the contractor's credentials, accept or bypass MFA, access Okta's internal support portal. The Okta support tool provided what Lapsus$ described as "god-like access" - the ability to view any customer's configuration, reset authenticators, and potentially impersonate customer accounts in support interactions. The 2022 breach prompted Okta to significantly restrict contractor access models and implement additional monitoring. However, the 2023 breach indicated those changes were insufficient.

The HAR File Breach (September-October 2023)

The 2023 breach was technically different but revealed persistent gaps in Okta's security practices. In September 2023, Okta's support team asked customers to upload HAR (HTTP Archive) files - recordings of browser traffic including all requests and responses - to help debug authentication issues. HAR files captured during Okta sessions contain session tokens, which can be used to impersonate the authenticated user.

An attacker obtained access to Okta's support case management system and downloaded HAR files that customers had uploaded to their support tickets. The HAR files contained session tokens for the customers who had uploaded them. BeyondTrust, Cloudflare, and 1Password were among the first to publicly disclose that they had detected suspicious activity using their Okta sessions - activity that turned out to be the attacker using session tokens harvested from their HAR files.

Cloudflare's post-incident analysis was particularly detailed and critical of Okta. Cloudflare noted that it had reported the suspicious activity to Okta on October 18, 2023, but that Okta did not confirm the breach had occurred until October 20 - two days during which the attacker potentially still had access to Okta's support system. 1Password similarly noted a gap between its report and Okta's confirmation.

[WARNING]
The Okta 2023 breach's scope was ultimately disclosed as all Okta customer support system users: approximately 134 companies had their support ticket data accessed, representing all customers who had opened support cases between September 28 and October 17, 2023. Okta's initial October 20 disclosure framed the breach as affecting approximately 1% of customers - approximately 134 of its 17,000+ customers. This framing was accurate but misleading given that the affected 1% included the largest, most security-sensitive Okta customers who were most likely to be interacting with support. The serial breach pattern - Okta suffering a significant incident in 2022, making changes, and then suffering another significant incident in 2023 - raised questions about whether the company's security improvements between the incidents were substantive or cosmetic. The dual incidents damaged enterprise confidence in Okta and contributed to renewed evaluation of identity provider security by many organizations. Okta's CEO and CISO published detailed post-incident communications after the 2023 breach that were more transparent than the 2022 response, acknowledging the company's delayed detection and the customer impact.

Identity Provider Security Implications

The Okta breaches crystallized several issues with how organizations think about identity provider security. An identity provider occupies a uniquely privileged position: it authenticates users for dozens or hundreds of downstream applications. A compromise of the identity provider is a compromise of all those applications.

The supply chain attack surface is particularly concerning. Organizations implement rigorous security controls for direct access to their systems but may not apply the same rigor to vendors who support those systems. Sitel's employee had access to Okta's customer support tools because Okta needed to provide that access for support operations - but the security of that access path was ultimately dependent on Sitel's security practices, which were outside Okta's direct control.

The HAR file incident highlighted a different problem: the security of artifacts that customers generate during support interactions. HAR files were a standard support debugging tool, but their content (session tokens, authentication cookies) made them sensitive artifacts that should be handled with the same care as credentials. Okta's support process of requesting HAR file uploads without adequate guidance about scrubbing sensitive tokens before upload created an inadvertent credential exposure mechanism.

[IOC]
Okta 2022 Lapsus$ breach: access via compromised Sitel Group contractor account, January 2022; access lasted approximately 5 days; scope: Okta support portal access with view/modify capability for customer configurations; disclosure: forced by Lapsus$ screenshots March 22, 2022; Okta initial public statement same day; CEO acknowledgment of inadequate communication March 25, 2022. Affected customers: Okta stated approximately 366 customers' data was viewable; actual customer impact was disputed. Lapsus$ members arrested UK March 24, 2022 (day after disclosure). Okta 2023 HAR file breach: access to Okta's support case management system via unknown initial access vector; session tokens in uploaded HAR files enabled attacker to impersonate customer sessions; access window September 28 - October 17, 2023; discovered by BeyondTrust, 1Password, and Cloudflare from suspicious activity in their Okta sessions; 134 affected customers disclosed October 20, 2023; revised scope November 2023: all customer support system users affected (HAR file metadata for all support tickets). Cloudflare confirmed attacker used a stolen session token to access their Okta admin console. 1Password detected suspicious activity September 29, 2023. Okta's 58-day detection gap between breach start (September 28) and first customer report discovery acknowledged in post-incident review.