All news
Security
24 October 2023

Okta's support system breach and the risk in your identity provider

Attackers accessed Okta's customer support case management system and used uploaded session files to target its customers.

What this means for your business

Your single sign-on provider is the master key to everything. If it's compromised, every connected app is exposed at once.

In October 2023 Okta disclosed that attackers had accessed its support case management system, obtaining HAR files that customers had uploaded for troubleshooting. Those files contained session tokens, which were then used against several Okta customers.

Why this matters even if you don't use Okta

Most small businesses use Microsoft Entra ID (formerly Azure AD) as their identity provider instead — same principle, same concentration of risk. Single sign-on is genuinely good for security, because it means fewer passwords and consistent MFA. It also means one account compromise reaches everything.

Reasonable precautions

  • Phishing-resistant MFA for administrators. Authenticator number-matching or a hardware key, not SMS.
  • Separate admin accounts that aren't used for day-to-day email and browsing.
  • Conditional access rules limiting sign-in from unexpected countries or unmanaged devices.
  • Watch for session hijacking, not just password theft. Modern attacks steal the cookie, not the password, so MFA alone doesn't always help.
  • Be careful what you upload to a support ticket. Browser traces and log bundles frequently contain live tokens.

We configure conditional access and admin separation as standard on the Microsoft 365 tenants we manage.

Worried this could affect you?

Cyber Essentials is the quickest way for a small business to close the gaps attackers use most.

See Cyber Essentials

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.