Okta
Disclosed Oct 20, 20232 years ago4,961 affectedConfirmed
Stolen credential gives attacker access to Okta customer support system
Okta said an attacker used a stolen credential to access its support case management system and view HAR files uploaded by some customers, which could contain session tokens. In November 2023 it said the attacker had also downloaded a report with the names and email addresses of all its customer support system users.
What is known
| People affected | 4,961 (as reported by the organization) |
|---|---|
| Disclosed | Oct 20, 2023 |
| Happened | Sep 23, 2023 |
| Attack | Hacking |
| Data exposed | Names, Emails, Credentials and tokens |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Oktaoag.ca.gov · Official notice | Official notice |
| Tracking Unauthorized Access to Okta's Support Systemsec.okta.com · The organization | The organization |
| Okta admits hackers accessed data on all customers during recent breachtechcrunch.com · News | News |
| Okta October Customer Support Security Incident: Update and Recommended Actions (8-K exhibit, Nov 29, 2023)sec.gov · SEC filing | SEC filing |
| Indiana Attorney General 2023 data breach report: Oktain.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Oct 20, 2023 | |
| California AGresidents of CA | Nov 1, 2023 | |
| Indiana AGresidents of IN | Nov 2, 2023 | 26 |
Other breaches at Okta
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Attackers copy Okta Workforce Identity Cloud source code from GitHubDec 21, 20223 years agoHackingUnverified | Dec 21, 20223 years ago | Hacking | Tech | Unverified | Unknown |
| Lapsus$ accesses Okta support engineer's machine at vendor SitelMar 22, 20224 years agoVendor breach | Mar 22, 20224 years ago | Vendor breach | Tech | Confirmed | Unknown |
History of this record
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 4961 · backfill source
- 2026-09-25 · attack: unknown to hacking · seed source
- 2026-09-25 · data_types: [] to ["names","emails","credentials"] · seed source
- 2026-09-25 · disclosed: 2023-11-01 to 2023-10-20 · seed source
- 2026-09-25 · summary: empty to Okta said an attacker used a stolen credential to access its support case management system and view HAR files uploaded by some customers, which could contain session tokens. In November 2023 it said the attacker had also downloaded a repor · seed source
- 2026-09-25 · title: empty to Stolen credential gives attacker access to Okta customer support system · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.