Massive identity theft campaign targeting Okta single sign-on at over 100 top businesses – make sure your firm stays safe

  • SLH targets ~100 enterprises with vishing attacks on Okta SSO credentials
  • Live Phishing Panel intercepts credentials and MFA tokens in real-time
  • No confirmed breaches yet, but hijacked Okta sessions pose severe risks

The notorious Scattered LAPSUS$ Hunters (SLH) threat actors are currently engaged in a massive identity theft campaign targeting Okta single sign-on (SSO) credentials at around 100 large enterprises.

Security researchers Silent Push found the hackers were currently running a sophisticated vishing (voice phishing) campaign, aimed at obtaining access to corporate infrastructure in order to exfiltrate sensitive data and then extort the victims for money.

The researchers said that SLH uses a new ‘Live Phishing Panel’, which allows their operators to “sit in the middle of a login session, intercepting credentials and MFA tokens in real-time”. In other words, the attackers would call the victims on the phone and get them to log into a service, while sitting “in the middle” and intercepting the secrets passing through.

Results unknown

Silent Push says that roughly 100 organizations from different verticals are being targeted. The entire list can be found here, and includes high-profile targets such as Atlassian, Morningstar, American Water, GameStop, and Telstra.

Being targeted, and being compromised are two entirely different things, though. There is no confirmation that any of the companies from the list were actually broken into, and at press time, there was no evidence of that being the case.

Silent Push told The Register it has “no intel to share” about potential victims, and SLH are yet to add anyone to their data leak website. The hackers did confirm that the number of targets was “close”.

The researchers said the risk of the campaign is great, because once an Okta session is hijacked, the attacker has a “skeleton key” to every app in the corporate environment. This allows them to extort sensitive data, move laterally, and even encrypt the data if needed.

“Standard security awareness training often fails to stop this specific threat. SLH operators are highly persuasive, frequently calling help desks and employees while simultaneously manipulating a live phishing page to match the victim’s specific login prompts,” the researchers explained.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Alienware’s fast 27-inch QD-OLED gaming monitor is 23 percent off

One of the best upgrades you can make to your gaming PC setup is an OLED monitor. Assuming that games already run great on...

This backup camera cleaner hides behind your license plate

The Lens Lizard is installed using your car’s existing license plate screw holes. | Image: Lens Lizard A Vermont-based startup has announced a new upgrade...

WordPress’ new AI assistant will let users edit their sites with prompts

Starting on Tuesday, WordPress users can edit their websites using the new AI assistant built into the platform's site editor and media library, TechCrunch...

Apple is reportedly planning to launch AI-powered glasses, a pendant, and AirPods

The second-gen Ray-Ban Meta smart glasses. | Photo by Amelia Holowaty Krales / The Verge Apple is pushing ahead with plans to launch its first...

Now Pixel 9 phones can transfer files with AirDrop, too

Google is expanding the AirDrop compatibility it first offered in the Pixel 10 (above). | Photo: Allison Johnson / The Verge When Google announced it...

Kingdom Come: Deliverance 2 and The Witcher 3 are coming to Game Pass

Xbox has revealed the second batch of Game Pass additions for February. There are quite a few heavyweights in the mix this time, including...

The first full trailer for The Mandalorian and Grogu is here

Fans of The Mandalorian and his tiny green apprentice Grogu are getting their best look yet at the duo's upcoming theatrical adventure, set for...

Netflix is streaming its first MMA fight on May 16

Netflix is streaming its very first live MMA fight on May 16. The combatants are one-time phenom Ronda Rousey and one-time actor Gina Carano....

WordPress adds an AI assistant

Web designers of the world: The Automattic-owned WordPress.com is further embracing AI on its platform. On Tuesday, it expanded its one-off AI site builder...

Netflix is adapting the board game Ticket to Ride

Netflix has been in the game adaptation business for a while now, but until recently most of its attention had been on adapting video...