{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des"},"incident":{"title":"Okta warns of a coordinated campaign against US customers' IT service desks","date":"2023-08","date_precision":"month","victim_org":"Multiple US-based Okta customer organizations","sector":"Technology","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in Okta's advisory.","outcomes":["Credential Theft","Data Breach","Insider Access"],"loss_usd":null,"loss_note":"Okta did not name victims or quantify losses in this advisory.","records_affected":null,"threat_actor":"Actor consistent with Scattered Spider / Muddled Libra (unnamed in the advisory)","summary":"Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.","how_it_worked":"The caller arrived already holding something: either the password to a privileged account or the ability to manipulate delegated authentication. That partial knowledge is what makes the help desk call succeed, because the agent hears a caller who knows their own username, manager and internal jargon, and treats an MFA reset as routine. Once the factors were reset the actor enrolled their own, signed in from anonymising proxies on unfamiliar devices, escalated to Super Administrator and stood up a second identity provider so they could impersonate arbitrary users through federation.","lessons":"Identity-proofing the caller out of band, such as manager attestation or video verification, plus admin-console policies that require phishing-resistant factors and known devices, breaks the reset-to-takeover chain.","confidence":"Confirmed","sources":[{"title":"Cross-Tenant Impersonation: Prevention and Detection","url":"https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/","publisher":"Okta Security"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"}],"entry_type":"campaign","slug":"2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des"}}