Site icon The IT Nerd

Okta Says Lapsus$ Breach Smaller Than First Thought…. I’m Not Sure I Buy That

Advertisements

Remember when Okta got pwned by Lapsus$, and it looked like over 300 customers were affected by this breach? Okta says an investigation into the January Lapsus$ breach concluded the incident’s impact was significantly smaller than expected. As in it only affected TWO customers.

Really?

I’m getting ahead of myself. Let’s start with this Tweet from Okta’s Co-founder and CEO:

Inside this Tweet is a report done by Okta’s Chief Security Officer David Bradbury. It’s very much worth reading, but I will hit the highlights for you:

I am not sure I am buying this. Here’s why. Their original rundown of this event went like this according to Okta at the time:

So if you look at this version of events and compare it to today’s version of events, it’s radically different. Thus I have to look at this and ask why is it radically different. I suspect that others watching this story will be asking similar questions. And I will be waiting to see how Okta explains that. If they can.

UPDATE: I got some commentary from Lucas Budman CEO of TruU:

It is great to hear that Okta’s customers were less affected than assumed, however, this breach was preventable. People assume that they are protected by multi-factor authentication (MFA), but the reality is that multi-factor authentication is not truly multi.  Passwords and second factor (2FA) technologies are easily compromised. It is time for the industry to move away from using weak forms of identification and towards truly passwordless MFA based authentication.

Exit mobile version