• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new report on okta hack reveals the entire episode lapsus$

New Report on Okta Hack Reveals the Entire Episode LAPSUS$ Attack

You are here: Home / General Cyber Security News / New Report on Okta Hack Reveals the Entire Episode LAPSUS$ Attack
March 29, 2022

An unbiased security researcher has shared what’s a in-depth timeline of gatherings that transpired as the notorious LAPSUS$ extortion gang broke into a third-party supplier linked to the cyber incident at Okta in late January 2022.

In a set of screenshots posted on Twitter, Monthly bill Demirkapi released a two-site “intrusion timeline” allegedly well prepared by Mandiant, the cybersecurity business hired by Sitel to investigate the security breach. Sitel, as a result of its acquisition of Sykes Enterprises in September 2021, is the 3rd-party service supplier that offers client support on behalf of Okta.

The authentication providers company revealed last 7 days that on January 20, it was alerted to a new factor that was extra to a Sitel client assist engineer’s Okta account, an endeavor that it stated was productive and blocked.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Automatic GitHub Backups

The incident only arrived to light-weight two months afterwards soon after LAPSUS$ posted screenshots on their Telegram channel as evidence of the breach on March 22.

The incident, which gave the menace actor accessibility to practically 366 Okta customers, transpired over a 5-working day window amongst January 16 and 21, during which the hackers carried out diverse phases of the attack, together with privilege escalation after getting an preliminary foothold, preserving persistence, lateral motion, and inner reconnaissance of the network.

Okta claimed that it experienced shared indicators of compromise with Sitel on January 21 and that it been given a summary report about the incident from Sitel only on March 17.

Subsequently, on March 22, the same working day the felony team shared the screenshots, it obtained a duplicate of the complete investigation report.

“Even when Okta gained the Mandiant report in March explicitly detailing the attack, they ongoing to dismiss the evident signals that their environment was breached until eventually LAPSUS$ shined a highlight on their inaction,” Demirkapi wrote in a tweet thread.

Prevent Data Breaches

The San Francisco-based organization, in a detailed FAQ posted on March 25, acknowledged that its failure to notify its people about the breach in January was a “oversight.”

“In light of the proof that we have collected in the very last week, it is clear that we would have built a distinctive decision if we experienced been in possession of all of the information that we have today,” Okta reported, introducing it “need to have extra actively and forcefully compelled data from Sitel.”

The improvement will come as the City of London Police instructed The Hacker News previous 7 days that 7 folks related to the LAPSUS$ gang have been arrested and subsequently produced under investigation. “Our enquiries keep on being ongoing,” the company included.

Uncovered this posting interesting? Adhere to THN on Facebook, Twitter  and LinkedIn to examine more exceptional material we article.


Some pieces of this post are sourced from:
thehackernews.com

Previous Post: «the ten biggest threats to your windows pc in 2022 The ten biggest threats to your Windows PC in 2022
Next Post: A Large-Scale Supply Chain Attack Distributed Over 800 Malicious NPM Packages a large scale supply chain attack distributed over 800 malicious npm»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • WhatsApp Unveils Proxy Support to Tackle Internet Censorship
  • Hackers Using CAPTCHA Bypass Tactics in Freejacking Campaign on GitHub
  • Blind Eagle Hacking Group Targets South America With New Tools
  • US Family Planning Non-Profit MFHS Confirms Ransomware Attack
  • Microsoft Reveals Tactics Used by 4 Ransomware Families Targeting macOS
  • Dridex Malware Now Attacking macOS Systems with Novel Infection Method
  • Cyber attacks on UK organisations surged 77% in 2022, new research finds
  • WhatsApp to combat internet blackouts with proxy server support
  • The IT Pro Podcast: Going passwordless
  • Podcast transcript: Going passwordless

Copyright © TheCyberSecurity.News, All Rights Reserved.