Desk live·
ForensicPost
Cloud/Identity/File 23-1020

Okta Support System Breach Exposed HAR Files Belonging to 134 Customers

Files uploaded by customers to troubleshoot their own problems contained live session tokens. An intruder with stolen credentials read them, and used them to hijack sessions at five customer organisations — including several security vendors who found it before Okta told them.

Constructed geometry · not a chart of case data
TargetOkta
ActorUnattributed
D. Kennedy10 min readConfidence: high2 sources reviewed

Okta confirmed on 20 October 2023 that an intruder had accessed files in its customer support case management system. In a later root-cause note the company put the window at 28 September to 17 October 2023 and the scope at 134 customers, described as under 1% of its customer base.

Access was obtained using stolen credentials. The files were HTTP Archive — HAR — captures, uploaded by customers so that support could reproduce their errors.

The Troubleshooting Format Is A Credential Format

A HAR file is a recording of browser network activity. That is what makes it useful for diagnosing a login problem, and it is also why it contains cookies and session tokens. The file does its job by capturing exactly the material an attacker needs.

Okta reported that the session tokens in those files were used to hijack the legitimate sessions of five customers. The company sanitised and revoked tokens embedded in shared HAR files as part of its response.

Customers Detected It First

BeyondTrust published its own account of identifying the breach of Okta’s support unit, and 1Password and Cloudflare were also among the affected customers. Several of the organisations that noticed were themselves security vendors with the tooling and the staff to spot an anomalous session.

That is the uncomfortable reading of this file. The detections that worked came from customers equipped to detect, which says very little about the 130-odd organisations that were not.

A Support System Is Production

The corpus returns to this at 25-0826, where Cloudflare disclosed that 104 API tokens were exposed because customers and staff had pasted them into support cases. Ticketing systems accumulate the material people paste under pressure, and they are almost never held to the standard of the systems they support.

How we reported this

Built on Okta’s own root-cause and remediation note, BeyondTrust’s published account, and contemporaneous reporting of the 134-customer figure. The window and the customer count are Okta’s. The count of five hijacked sessions is Okta’s. This desk has not independently verified which customers were affected beyond those that published their own accounts. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Unauthorized Access to Okta’s Support Case Management System: Root Cause and RemediationOkta Security
  2. BeyondTrust Discovers Breach of Okta Support UnitBeyondTrust
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary