Updated Okta Statement on Lapsus$
1–10 of 239 posts
Re: Updated Okta Statement on Lapsus$
#2Re: Updated Okta Statement on Lapsus$
#3Re: Updated Okta Statement on Lapsus$
#4This means they could have reset anybody’s credentials and logged in. There would a record of it if the audit logs are valid, but saying no action is needed may be a stretch.
Re: Updated Okta Statement on Lapsus$
#5Re: Updated Okta Statement on Lapsus$
#6Very ambiguous statement, not really fitting in with the whole "deeply committed to transparency" image they are trying to emit.
What does "facilitate" really refer to here? If it was just triggering it, they would have said so, presumably. And why is only passwords mentioned as what couldn't be obtained and not the tokens from MFA as well, does that mean they could obtain those tokens?
I wonder how it fits in with the groups own statements that they still have active access. Gonna be interesting to see what Lapsus$ replies to this statement.
Re: Updated Okta Statement on Lapsus$
#7It looked kinda successful though...
Re: Updated Okta Statement on Lapsus$
#8Re: Updated Okta Statement on Lapsus$
#9Re: Updated Okta Statement on Lapsus$
#10> Support engineers do have access to limited data - for example, Jira tickets and lists of users - that were seen in the screenshots. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. This means they could have reset anybody’s credentials and logged in. There would a record of it if the audit logs are valid, but saying no act…
Does it? It specifically says "but are unable to obtain those passwords," which reads to me like they are able to trigger a password reset email to the user, but are not actually able to set the password themselves.