{
  "id": "case-okta-lapsus",
  "slug": "okta-lapsus-support-engineer-breach",
  "title": "Okta Customer Support Console Intrusion (LAPSUS$)",
  "summary": "Teenage cyber extortion collective LAPSUS$ compromised a third-party customer support contractor (Sitel) workstation via an active RDP session, gaining access to Okta SuperUser administrative diagnostic tools affecting 366 enterprise tenants.",
  "case_number": "City of London Police / FBI Joint Action",
  "court": "Southwark Crown Court (UK)",
  "district": "London / S.D.N.Y.",
  "country": "United States",
  "opened_at": "2022-03-22",
  "status": "convicted",
  "victim_sector": "Identity & Cloud Services",
  "victim_country": "United States",
  "loss_amount_usd": 20000000,
  "loss_amount_note": "Tenant security audits, forensic investigations, and market value disruption.",
  "first_seen_at": "2022-01-21T00:00:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "lapsus",
  "defendant_slugs": [
    "arion-kurtaj"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "The attackers obtained valid credentials to the Sitel corporate network, accessing an internal engineer thin client connected to the support intranet.",
      "evidence_locator": "Okta Security Incident Statement",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Okta Incident Retrospective",
      "source_url": "https://sec.okta.com",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1113",
      "evidence_excerpt": "Adversaries captured screenshots of internal SuperUser support consoles and customer Slack channels, publishing them to Telegram channels to substantiate extortion demands.",
      "evidence_locator": "CISA Alert on Lapsus$ Tactics",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory on LAPSUS$",
      "source_url": "https://www.cisa.gov",
      "technique_name": "Screen Capture",
      "tactic": "Collection"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2022-01-21",
      "description": "LAPSUS$ actors access a customer support engineer workstation at Sitel for a 5-day window."
    },
    {
      "event_type": "disclosure",
      "event_date": "2022-03-22",
      "description": "LAPSUS$ posts screenshots of Okta internal tools to Telegram; Okta confirms 366 customers were impacted."
    },
    {
      "event_type": "verdict",
      "event_date": "2023-08-23",
      "description": "Arion Kurtaj convicted in Southwark Crown Court in London for cyber extortion and hacking offenses."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Remote Desktop compromise of a third-party customer support engineer at Sitel (Sykes) who possessed legitimate access to Okta internal SuperUser customer support applications.",
    "blast_radius": "LAPSUS$ accessed the internal Okta support console for five days, gaining the ability to initiate password resets and inspect authentication tenant configurations for hundreds of high-profile Okta enterprise customers.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Third-Party Support Machine Compromise",
        "description": "Threat actors used infostealer malware credentials to gain RDP access to a contract support engineer workstation at Sitel.",
        "technical_artifacts": [
          "RedLine stealer credentials",
          "RDP connection logs"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Privilege Abuse",
        "title": "Privilege Abuse via SuperUser Console",
        "description": "The attackers utilized the engineer active session to access Okta internal customer support portal (SuperUser) without tripping MFA alerts.",
        "technical_artifacts": [
          "SuperUser support portal session",
          "Browser session hijacking"
        ],
        "mitre_technique_id": "T1078.004"
      },
      {
        "phase": "Internal Reconnaissance",
        "title": "Slack & Internal Wiki Reconnaissance",
        "description": "Operatives captured screenshots of internal ticket queues, tenant metadata, and administrative communication channels.",
        "technical_artifacts": [
          "Slack screenshot captures",
          "Confluence documentation views"
        ],
        "mitre_technique_id": "T1005"
      },
      {
        "phase": "Target Querying",
        "title": "Customer Tenant Investigation",
        "description": "Attackers searched for high-profile corporate accounts, attempting to view multi-factor reset logs and customer tenant identities.",
        "technical_artifacts": [
          "SuperUser audit trail logs",
          "Tenant query records"
        ],
        "mitre_technique_id": "T1530"
      },
      {
        "phase": "Public Extortion",
        "title": "Extortion & Public Telegram Leak",
        "description": "LAPSUS$ published screenshots on Telegram to humiliate Okta, bypass extortion negotiation, and create enterprise trust crises.",
        "technical_artifacts": [
          "Telegram channel postings",
          "Extortion claim screenshots"
        ],
        "mitre_technique_id": "T1651"
      }
    ],
    "defensive_takeaways": [
      "Enforce zero-trust device posture checks for third-party contractors and managed service providers accessing administrative consoles.",
      "Require step-up re-authentication with FIDO2 hardware tokens when initiating sensitive customer tenant administrative actions.",
      "Log and alert on anomalous administrative query volumes in customer support tooling.",
      "Audit third-party vendor security standards and require prompt incident notification SLAs."
    ]
  }
}