Okta Customer Support Console Intrusion (LAPSUS$)
Key Facts
- Legal Status: CONVICTED in Southwark Crown Court (UK).
- Primary Target Sector: Identity & Cloud Services.
- Documented Financial Loss: $20.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Remote Desktop compromise of a third-party customer support engineer at Sitel (Sykes) who possessed legitimate access to Okta internal SuperUser customer support applications.
Operational & Financial Fallout
LAPSUS$ accessed the internal Okta support console for five days, gaining the ability to initiate password resets and inspect authentication tenant configurations for hundreds of high-profile Okta enterprise customers.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Remote Desktop compromise of a third-party customer support engineer at Sitel (Sykes) who possessed legitimate access to Okta internal SuperUser customer support applications.
Adversary Kill Chain Flow
5 Documented PhasesThreat actors used infostealer malware credentials to gain RDP access to a contract support engineer workstation at Sitel.
The attackers utilized the engineer active session to access Okta internal customer support portal (SuperUser) without tripping MFA alerts.
Operatives captured screenshots of internal ticket queues, tenant metadata, and administrative communication channels.
Attackers searched for high-profile corporate accounts, attempting to view multi-factor reset logs and customer tenant identities.
LAPSUS$ published screenshots on Telegram to humiliate Okta, bypass extortion negotiation, and create enterprise trust crises.
LAPSUS$ accessed the internal Okta support console for five days, gaining the ability to initiate password resets and inspect authentication tenant configurations for hundreds of high-profile Okta enterprise customers.
Procedural & Incident Timeline
LAPSUS$ actors access a customer support engineer workstation at Sitel for a 5-day window.
LAPSUS$ posts screenshots of Okta internal tools to Telegram; Okta confirms 366 customers were impacted.
Arion Kurtaj convicted in Southwark Crown Court in London for cyber extortion and hacking offenses.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "The attackers obtained valid credentials to the Sitel corporate network, accessing an internal engineer thin client connected to the support intranet." | Okta Security Incident Statement | reviewed |
| T1113 | Screen Capture Collection | "Adversaries captured screenshots of internal SuperUser support consoles and customer Slack channels, publishing them to Telegram channels to substantiate extortion demands." | CISA Alert on Lapsus$ Tactics | reviewed |