{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling"},"incident":{"title":"Lapsus$ rides a Sitel support engineer's laptop into Okta's admin tooling","date":"2022-01-21","date_precision":"day","victim_org":"Okta (via subprocessor Sitel/Sykes)","sector":"Technology","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"Okta did not disclose a financial loss figure.","records_affected":null,"threat_actor":"Lapsus$","summary":"A threat actor gained remote control of a laptop belonging to a support engineer at Sitel/Sykes, a customer-support subprocessor for Okta, and used the engineer's delegated access to Okta's internal SuperUser application. Okta initially said up to 366 customers were potentially exposed but its concluded investigation found the actor had hands-on-keyboard access for 25 minutes on 21 January 2022 and reached two customer tenants. Lapsus$ published screenshots in March 2022, forcing disclosure.","how_it_worked":"Lapsus$ specialised in abusing the human layer of outsourced IT: support agents at business-process outsourcers hold standing, broadly scoped access to customer tenants but sit outside the customer's own security controls. Having taken over a Sitel engineer's workstation, the actor inherited that trusted seat and drove the Okta SuperUser console as the agent, in the agent's session, from the agent's device. No password or MFA prompt was presented to the attacker because the legitimate operator had already satisfied them. The blast radius was limited only by what the support role could do.","lessons":"Outsourced support seats need the same scrutiny as privileged internal admins: just-in-time, scoped, session-recorded access with device trust, rather than standing tenant-wide impersonation rights.","confidence":"Confirmed","sources":[{"title":"Okta Concludes its Investigation Into the January 2022 Compromise","url":"https://www.okta.com/blog/company-and-culture/okta-concludes-its-investigation-into-the-january-2022-compromise/","publisher":"Okta"},{"title":"Okta says hundreds of companies impacted by security breach","url":"https://techcrunch.com/2022/03/23/okta-breach-sykes-sitel/","publisher":"TechCrunch"}],"entry_type":"incident","slug":"2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling"}}