🚀 ProPicks AI Hits +34.9% Return!Read Now

Okta's fallout impacts Cloudflare and 1Password

Published 25/10/2023, 02:50 pm
© Reuters.  Okta's fallout impacts Cloudflare and 1Password
OKTA
-
NET
-

Network security behemoth Cloudflare (NYSE:NET) and password management firm 1Password have revealed that they were momentarily targeted by hackers following a recent security incident at single sign-on solution provider Okta's customer support unit.

Both companies confirmed that the intrusions did not compromise their customer systems or user data.

Okta reported late on Friday last that its customer support unit had been compromised.

Hackers gained access to files containing sensitive information such as browser recording sessions, cookies and session tokens.

According to Okta spokesperson Vitor De Souza, around 1% of its 17,000 corporate customers, or 170 organisations, were affected.

Okta says the incident affected a “very small number” of customers, however it appears the hackers responsible had access to Okta’s support platform for at least two weeks before the company fully contained the intrusion, says Brian Krebs, the security journalist who first reported the inident.

This incident marks another security issue for Okta, following the theft of its source code in December 2022 and a separate incident in January 2022.

"Immediately halted"

Pedro Canahuati, chief technology officer at 1Password, stated in a blog post that the intrusion was immediately halted and subsequent investigations showed no compromise of user data. "We’ve confirmed that this was a result of Okta’s support system breach," said Canahuati.

Both 1Password and Cloudflare reported that the hackers had used session tokens, extracted from files uploaded to Okta's support system for technical troubleshooting, to gain limited access.

Security firm BeyondTrust also indicated that it was impacted by the Okta breach but had quickly terminated the intrusion.

Okta's share price plummeted over 11% on Friday, erasing at least US$2 billion from the company’s market value.

The news comes as part of a broader conversation surrounding cybersecurity vulnerabilities in the tech sector, raising questions about how interconnected systems can be exploited.

Read more on Proactive Investors AU

Disclaimer

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.