Okta confirmed on 20 October 2023 that an intruder had accessed files in its customer support case management system. In a later root-cause note the company put the window at 28 September to 17 October 2023 and the scope at 134 customers, described as under 1% of its customer base.
Access was obtained using stolen credentials. The files were HTTP Archive — HAR — captures, uploaded by customers so that support could reproduce their errors.
The Troubleshooting Format Is A Credential Format
A HAR file is a recording of browser network activity. That is what makes it useful for diagnosing a login problem, and it is also why it contains cookies and session tokens. The file does its job by capturing exactly the material an attacker needs.
Okta reported that the session tokens in those files were used to hijack the legitimate sessions of five customers. The company sanitised and revoked tokens embedded in shared HAR files as part of its response.
Customers Detected It First
BeyondTrust published its own account of identifying the breach of Okta’s support unit, and 1Password and Cloudflare were also among the affected customers. Several of the organisations that noticed were themselves security vendors with the tooling and the staff to spot an anomalous session.
That is the uncomfortable reading of this file. The detections that worked came from customers equipped to detect, which says very little about the 130-odd organisations that were not.
A Support System Is Production
The corpus returns to this at 25-0826, where Cloudflare disclosed that 104 API tokens were exposed because customers and staff had pasted them into support cases. Ticketing systems accumulate the material people paste under pressure, and they are almost never held to the standard of the systems they support.
Built on Okta’s own root-cause and remediation note, BeyondTrust’s published account, and contemporaneous reporting of the 134-customer figure. The window and the customer count are Okta’s. The count of five hijacked sessions is Okta’s. This desk has not independently verified which customers were affected beyond those that published their own accounts. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.