On 20 January 2022 Okta’s security team was alerted that a new factor had been added to the account of a customer support engineer at Sitel, a third-party support provider. Reporting places the intruders inside Sitel’s network from 16 to 21 January, holding remote desktop access to a Sitel machine that was logged into Okta.
Okta later stated that 366 customers — around 2.5% of its base — may have been affected. Those customers learned of the incident on 22 March, when the Lapsus$ group published screenshots of Okta’s internal systems.
On 19 April 2022 Okta published the conclusion of its forensic investigation and revised that figure sharply downward: two customer tenants were actually accessed, not 366. The reason given was the window — the attacker is reported to have had control of the Sitel workstation for 25 consecutive minutes on 21 January. Okta also ended its relationship with Sitel and said it would directly manage third-party devices with access to its support tools.
A Ceiling Is Not A Count
The 366 figure was a maximum potential exposure — every tenant the compromised support account could in principle have reached. It was widely reported, including by this desk, as though it described impact.
The distinction matters in both directions. An organisation that publishes only the ceiling invites a number it will spend months walking back; one that publishes only the confirmed count during an unfinished investigation understates what it does not yet know. The corpus records the same tension at 22-1104b, where a scale arrived three months late from the attacker, and at 23-0715, where a volume figure was attributed to two different operations. This file now carries both numbers, in order, because the sequence is the finding.
Two Months Is The Finding
The alert fired on day one. The gap is not detection; it is what happened next. Sitel engaged a forensics firm whose investigation concluded on 10 March, and the report reached Okta on 17 March. Five days later the attackers published, and everyone found out together.
Okta subsequently said it had made a mistake in delaying disclosure. The corpus records the same shape at 26-0721b, where a notification arrived 289 days after the intrusion, and argues throughout that a notification clock which starts at a determination the notifying party controls is not a clock at all. Here the determination was outsourced too.
What An Identity Provider Is For
An identity provider is a single deliberate concentration: every customer accepts one authority over who is allowed in, in exchange for not maintaining that authority themselves. The trade is sound and the concentration is the point.
What this file records is that the concentration extended past the company holding it. The support desk was contracted out, and the account that mattered belonged to the contractor. The corpus files the identical arrangement at 26-0713 — the support ticket is the breach — and at 25-0818. This is the earliest instance the database now holds.
The Factor Was Added, Not Stolen
The detection signal was an enrolment: a new authentication factor attached to an existing account. That is not a password being guessed. It is the account recovery path being used as designed, by someone who should not have had it.
The corpus records the same mechanism at 23-0913, where a synced authenticator turned a second factor into no factor, and at 25-0421b, where adversaries logged in with valid credentials in 56% of engagements. Enrolment is the part of an identity system that has to stay usable for people who have genuinely lost a device, and that is precisely why it is the part worth attacking.
Built on contemporaneous reporting of the incident and of Okta’s own statements. The 20 January alert, the 16–21 January intrusion window at Sitel, the RDP access, the 366 customers / 2.5% figure, the 10 March conclusion of the forensic investigation, the 17 March delivery of the report and the 22 March publication by Lapsus$ are as reported at the time. Revised 2026: this file previously ended on the 366 figure. Okta’s 19 April 2022 final report put actual access at two customer tenants and attributed the limited impact to a 25-minute window of control on 21 January; that correction, and the termination of the Sitel relationship, are as reported and are now carried above. This desk has not seen the forensic report. Sitel is named because Okta named it. No individual is named. Graded high on the sequence and the disclosure gap, which are well documented, rather than on the internal detail of what was reached. Corrections: corrections@forensicpost.com.