Okta Took Two Months to Tell Anyone

Okta Took Two Months to Tell Anyone

Tech News breach infosec lapsus okta security

So Okta finally admitted something this week that a lot of us in the identity-and-access-management world had already half-figured out from screenshots floating around Telegram: Lapsus$, the hacking crew that's been on a real tear lately, had access to an internal support engineer's laptop back in January. Okta's own timeline says it was contained back then. The problem is nobody outside the company knew that until the group itself posted screenshots on March 22nd, and Okta spent the next couple of days doing that thing companies do where the story keeps "clarifying" itself in ways that make you trust it less, not more.

First it was "no impact." Then it was maybe 2.5% of customers, something like 366 organizations, could have been touched through that support engineer's session. I use Okta at my day job for SSO into basically everything, so this isn't some abstract industry-news thing for me, it's "did someone potentially have a window into resetting my coworkers' passwords for five days in January and we're only hearing about it in March." That gap is the actual story here, not the breach itself. Breaches happen. Everybody gets popped eventually if the attacker is patient and a little lucky. What matters is whether you tell people promptly and honestly, and Okta's initial answer to both of those was pretty clearly no.

And it wasn't just Okta this week. Microsoft put out a post from their threat intel team confirming the same group, they're calling them DEV-0537 internally, got into one of their systems too and grabbed partial source code for some Bing and Cortana components. Microsoft's angle on it was basically "we don't rely on code secrecy for security so this doesn't really move the needle," which, fine, that's probably true as far as it goes, but it's also the kind of statement that's technically correct and still feels like spin when you read it next to the Okta mess.

Then on top of all that, City of London Police said they'd arrested seven people, teenagers mostly, 16 to 21 years old, in connection with the Lapsus$ investigation. No confirmation these are "the" core members, and honestly with a group like this that's been hitting Nvidia, Samsung, Ubisoft, and now Okta and Microsoft all in the space of like six weeks, it wouldn't shock me if it's a loose crew where arresting a few people barely slows anything down. Groups like this seem to recruit and rotate fast, especially when a lot of the participants are still teenagers who apparently coordinate over Discord and Telegram like it's a group project.

What I keep coming back to, though, is the disclosure timing thing, because it's not really about Okta specifically. It's about how every company handles this now: quietly "contain" the incident, decide internally that it's not material enough to tell anyone, and then only actually come clean once you're forced to because someone posted proof publicly. If the screenshots hadn't leaked, would we know about any of this right now? I'd bet not. And that's a genuinely bad incentive structure for an industry where half the pitch of these identity platforms is "trust us with the keys to literally everything."

I don't think Okta is uniquely bad here, for what it's worth. I think this is just what happens when incident response gets run through a legal and PR filter before it gets run through an "our customers deserve to know" filter. I've sat in enough vendor security reviews at work over the past year to know that the fancy SOC 2 report and the reassuring paragraph on the trust page don't actually tell you much about how a company behaves when something goes wrong for real. You find that out later, usually the hard way, usually from a leak instead of a disclosure.

Anyway. If you're an admin on Okta and you haven't rotated credentials or at least reviewed your support engineer access logs from January, that's probably worth an afternoon this week. Not because I think there's some lingering active compromise, but because "probably fine" isn't really something I want to take on faith from a company that took two months to tell me about the first incident.