CASE DOSSIER convicted

Okta Customer Support Console Intrusion (LAPSUS$)

Docket: City of London Police / FBI Joint Action Court: Southwark Crown Court (UK) Opened: 2022-03-22 Sector: Identity & Cloud Services

Key Facts

Status
CONVICTED
Legal disposition
Loss Amount
$20.0 million
Tenant security audits, forensic investigations, and market value disruption.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: CONVICTED in Southwark Crown Court (UK).
  • Primary Target Sector: Identity & Cloud Services.
  • Documented Financial Loss: $20.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Teenage cyber extortion collective LAPSUS$ compromised a third-party customer support contractor (Sitel) workstation via an active RDP session, gaining access to Okta SuperUser administrative diagnostic tools affecting 366 enterprise tenants.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Remote Desktop compromise of a third-party customer support engineer at Sitel (Sykes) who possessed legitimate access to Okta internal SuperUser customer support applications.

Operational & Financial Fallout

LAPSUS$ accessed the internal Okta support console for five days, gaining the ability to initiate password resets and inspect authentication tenant configurations for hundreds of high-profile Okta enterprise customers.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: CONVICTED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Remote Desktop compromise of a third-party customer support engineer at Sitel (Sykes) who possessed legitimate access to Okta internal SuperUser customer support applications.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Access Third-Party Support Machine Compromise
MITRE ATT&CK T1078 →

Threat actors used infostealer malware credentials to gain RDP access to a contract support engineer workstation at Sitel.

Artifacts & Tooling: RedLine stealer credentials RDP connection logs
2
Privilege Abuse Privilege Abuse via SuperUser Console
MITRE ATT&CK T1078.004 →

The attackers utilized the engineer active session to access Okta internal customer support portal (SuperUser) without tripping MFA alerts.

Artifacts & Tooling: SuperUser support portal session Browser session hijacking
3
Internal Reconnaissance Slack & Internal Wiki Reconnaissance
MITRE ATT&CK T1005 →

Operatives captured screenshots of internal ticket queues, tenant metadata, and administrative communication channels.

Artifacts & Tooling: Slack screenshot captures Confluence documentation views
4
Target Querying Customer Tenant Investigation
MITRE ATT&CK T1530 →

Attackers searched for high-profile corporate accounts, attempting to view multi-factor reset logs and customer tenant identities.

Artifacts & Tooling: SuperUser audit trail logs Tenant query records
5
Public Extortion Extortion & Public Telegram Leak
MITRE ATT&CK T1651 →

LAPSUS$ published screenshots on Telegram to humiliate Okta, bypass extortion negotiation, and create enterprise trust crises.

Artifacts & Tooling: Telegram channel postings Extortion claim screenshots
Real-World Blast Radius & Operational Fallout

LAPSUS$ accessed the internal Okta support console for five days, gaining the ability to initiate password resets and inspect authentication tenant configurations for hundreds of high-profile Okta enterprise customers.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce zero-trust device posture checks for third-party contractors and managed service providers accessing administrative consoles.
✓ Require step-up re-authentication with FIDO2 hardware tokens when initiating sensitive customer tenant administrative actions.
✓ Log and alert on anomalous administrative query volumes in customer support tooling.
✓ Audit third-party vendor security standards and require prompt incident notification SLAs.

Procedural & Incident Timeline

2022-01-21 incident

LAPSUS$ actors access a customer support engineer workstation at Sitel for a 5-day window.

2022-03-22 disclosure

LAPSUS$ posts screenshots of Okta internal tools to Telegram; Okta confirms 366 customers were impacted.

2023-08-23 verdict

Arion Kurtaj convicted in Southwark Crown Court in London for cyber extortion and hacking offenses.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"The attackers obtained valid credentials to the Sitel corporate network, accessing an internal engineer thin client connected to the support intranet." Okta Security Incident Statement reviewed
T1113 Screen Capture
Collection
"Adversaries captured screenshots of internal SuperUser support consoles and customer Slack channels, publishing them to Telegram channels to substantiate extortion demands." CISA Alert on Lapsus$ Tactics reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Okta Customer Support Console Intrusion (LAPSUS$), No. City of London Police / FBI Joint Action (Southwark Crown Court (UK) 2022), https://cybercaselibrary.com/cases/okta-lapsus-support-engineer-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/okta-lapsus-support-engineer-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>