Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned.

  • Unaware7013@kbin.social
    link
    fedilink
    arrow-up
    10
    ·
    8 months ago

    We urge Okta to consider implementing the following best practices, including:

    Take any report of compromise seriously and act immediately to limit damage; in this case Okta was first notified on October 2, 2023 by BeyondTrust but the attacker still had access to their support systems at least until October 18, 2023

    Holy shit, this is absolutely beyond negligent for an authentication platform.