Connecting a few dots why, while the headline seems misleading, it might matter. 1. Okta employee PII and foreign key to employee health info (a particularly sensitive class of PII) may be exposed. “On October 12, 2023, Rightway informed Okta that an unauthorized actor gained access to an eligibility census file maintained by Rightway in its provision of services ...” https://www.documentcloud.org/documents/24110001-…
Real-talk, if you were calling the shots at Okta, what would you do here?
Enforce hardware-key MFA everywhere, for every vendor service? Impose a no-professional-social-media policy for all employees? This probably is too late to do any good, but it's pretty clear phishing is a hot vector right now.