October 20, 2023 By Sergiu Gatlan
Okta says attackers accessed files containing cookies and session tokens uploaded by customers to its support management system after breaching it using stolen credentials.
"The threat actor was able to view files uploaded by certain Okta customers as part of recent support cases," said Okta's Chief Security Officer David Bradbury.
"It should be noted that the Okta support case management system is separate from the production Okta service, which is fully operational and has not been impacted."
Okta's CSO added that this incident did not impact the Auth0/CIC case management system. Okta notified all customers' whose Okta environment or support tickets were impacted by the incident. Those who haven't received an alert are not affected.