Two Months Is a Long Time to Sit on a Breach

Two Months Is a Long Time to Sit on a Breach

Tech News breaches okta security sso

I got one of those emails Monday morning. You know the kind, "we are writing to inform you of a security incident that may have affected your organization." My company runs its SSO through Okta, so did roughly a zillion other companies, and this week a lot of us got to find out that the login page holding together our entire work life had a stranger poking around inside it back in January.

If you missed it: a group calling themselves Lapsus$ (yes, with the dollar sign, no I dont know why) posted a pile of screenshots late last week showing they'd been sitting inside a support engineer's machine, over at a contractor Okta uses called Sitel. Not Okta's own network, technically, a sub-processor's laptop. The screenshots showed Slack, ticketing systems, and what looked like the internal tools support staff use to reset passwords and MFA for customer accounts. Thats the part that got everyone's attention, because if you can reset MFA on a company's Okta tenant you can basically walk in the front door of that company.

Oktas first public response was pretty breezy, something like "we have concluded that there is no action for customers to take," and I get why they'd want to say that fast to stop the bleeding on Twitter, but it did not age great. A day or so later Oktas CEO was posting a more detailed timeline: the actual incident happened back in mid-January, they knew about it then, a forensics firm looked into it and closed the case, and this weeks screenshots were basically Lapsus$ showing off something old rather than something new. The number going around afterward was something like 2.5 percent of customers, maybe 366 companies if I'm remembering right, could have had some exposure during a five day window in January.

Heres the part that actually bugs me, and its not really about Lapsus$ specifically. Its the two months. If a five day window in mid-January is genuinely when the exposure happened, that means Okta knew there was something worth investigating back then, ran an investigation, and never told the customers who might have been in that blast radius until a hacking group forced their hand by posting screenshots. I dont think thats some rare moral failing unique to Okta. I think its just what happens by default when a vendor is the one deciding whether their own incident is "material enough" to bother you with. Nobody wants to be the company that emails ten thousand customers to say "hey, minor thing, probably fine" and then it turns out to actually matter. So the incentive is always to sit on it, close the ticket quietly, and only talk when somebody else makes you.

I spent a chunk of the afternoon digging through our own Okta admin console at work, checking session logs for anything from mid-January that looked off, which, three hours in, mostly just gave me a headache and a new appreciation for how much of my job now runs downstream of a single login provider I dont control and cant really audit. Thats the actual lesson here for me, more than "Lapsus$ bad" or "Okta should have said something sooner." Weve centralized identity into a handful of companies because it genuinely is more convenient than every app having its own password, and Im not saying we should go back to that either, that was worse in different ways, ask anyone who used fifteen separate logins in 2009. But convenience like that comes with a blast radius, and the blast radius stays invisible right up until a Telegram channel posts screenshots of somebody's support ticket queue.

Small aside, because I cant let it go: Im also stuck on the group's name. Lapsus$ with a dollar sign sitting where the S should go, like a company logo from 2003. Half the security world is calling them a loosely organized bunch of teenagers at this point given some of their targets and the sloppy operational security, and I believe it, because a more disciplined crew would have sat on that access a lot longer instead of posting screenshots to flex on Telegram.

Go check your MFA settings this week. Rotate anything that's felt stale for a while. And dont hold your breath waiting for the next vendor breach notice to show up on time, because on current evidence it wont.