What happened
Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.
How the deception worked
The caller arrived already holding something: either the password to a privileged account or the ability to manipulate delegated authentication. That partial knowledge is what makes the help desk call succeed, because the agent hears a caller who knows their own username, manager and internal jargon, and treats an MFA reset as routine. Once the factors were reset the actor enrolled their own, signed in from anonymising proxies on unfamiliar devices, escalated to Super Administrator and stood up a second identity provider so they could impersonate arbitrary users through federation.
AI involvement · No AI reported
No AI involvement reported in Okta's advisory.
The control that would have caught it· our reading, not a claim from the sources
Identity-proofing the caller out of band, such as manager attestation or video verification, plus admin-console policies that require phishing-resistant factors and known devices, breaks the reset-to-takeover chain.
Sources (2)
- Cross-Tenant Impersonation: Prevention and DetectionOkta Security·sec.okta.comOpen ↗
- Scattered Spider (AA23-320A)CISA / FBI·cisa.govOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.