In October 2023 Okta disclosed that attackers had accessed its support case management system, obtaining HAR files that customers had uploaded for troubleshooting. Those files contained session tokens, which were then used against several Okta customers.
Why this matters even if you don't use Okta
Most small businesses use Microsoft Entra ID (formerly Azure AD) as their identity provider instead — same principle, same concentration of risk. Single sign-on is genuinely good for security, because it means fewer passwords and consistent MFA. It also means one account compromise reaches everything.
Reasonable precautions
- Phishing-resistant MFA for administrators. Authenticator number-matching or a hardware key, not SMS.
- Separate admin accounts that aren't used for day-to-day email and browsing.
- Conditional access rules limiting sign-in from unexpected countries or unmanaged devices.
- Watch for session hijacking, not just password theft. Modern attacks steal the cookie, not the password, so MFA alone doesn't always help.
- Be careful what you upload to a support ticket. Browser traces and log bundles frequently contain live tokens.
We configure conditional access and admin separation as standard on the Microsoft 365 tenants we manage.