What happened
BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.
How the deception worked
Callers posed as the target company's own IT team and offered to help the employee set up passkeys, a request timed to coincide with genuine passwordless rollouts. The employee was directed to a lookalike SSO page that relayed every keystroke to the real Okta login in real time. As the victim typed, the attacker was logging in alongside them, so the MFA challenge the victim saw on their phone matched the one they expected, and the one-time code they read out was immediately replayed. With a live session, attackers reached every application behind SSO.
AI involvement · Suspected AI-enabled
Mandiant documented this actor set using voice phishing with AI voice agents and company-branded phishing sites; AI use in individual calls was not separately confirmed.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant, origin-bound authentication such as FIDO2 passkeys with device trust makes real-time credential relay useless, since the credential will not release to a lookalike domain.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.