1. Okta employee PII and foreign key to employee health info (a particularly sensitive class of PII) may be exposed.
“On October 12, 2023, Rightway informed Okta that an unauthorized actor gained access to an eligibility census file maintained by Rightway in its provision of services ...”
https://www.documentcloud.org/documents/24110001-okta-indivi...
The file contained the following information on current and former Okta employees and their dependents:
- Full names
- Social Security Numbers (SSNs)
- Health or Medical Insurance plan number
2. Okta and its customer pool are known to be under an aggressive series of phishing and social engineering attacks.
3. This type of information makes those attacks more effective.
So while this particular breach starts as a Rightway problem, the nature of what was taken puts Okta itself at additional risk, as attackers build their social engineering / phishing dossier while looking for ways to get into Okta and/or get to Okta's customers in bulk.