https://www.bleepingcomputer.com/news/security/okta-says-its-github-account-hacked-source-code-stolen/ BleepingComputer.com logo * * * [ ] [Login] [Sign up] * * * [ ] [Login] [Sign up] * News + Featured + Latest + Microsoft pushes emergency fix for Windows Server Hyper-V VM issues Microsoft pushes emergency fix for Windows Server Hyper-V VM issues + Raspberry Robin worm drops fake malware to confuse researchers Raspberry Robin worm drops fake malware to confuse researchers + Hackers bombard PyPi platform with information-stealing malware Hackers bombard PyPi platform with information-stealing malware + Microsoft will turn off Exchange Online basic auth in January Microsoft will turn off Exchange Online basic auth in January + Samsung and Google fix Microsoft Intune Android 13 enrollment issue Samsung and Google fix Microsoft Intune Android 13 enrollment issue + Corsair keyboard bug makes it type on its own, no malware involved Corsair keyboard bug makes it type on its own, no malware involved + Zerobot malware now spreads by exploiting Apache vulnerabilities Zerobot malware now spreads by exploiting Apache vulnerabilities + FCC proposes record-breaking $300 million fine against robocaller FCC proposes record-breaking $300 million fine against robocaller * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * Virus Removal Guides + Latest + Most Viewed + Ransomware + Remove the Theonlinesearch.com Search Redirect Remove the Theonlinesearch.com Search Redirect + Remove the Smartwebfinder.com Search Redirect Remove the Smartwebfinder.com Search Redirect + How to remove the PBlock+ adware browser extension How to remove the PBlock+ adware browser extension + Remove the Toksearches.xyz Search Redirect Remove the Toksearches.xyz Search Redirect + Remove Security Tool and SecurityTool (Uninstall Guide) Remove Security Tool and SecurityTool (Uninstall Guide) + How to remove Antivirus 2009 (Uninstall Instructions) How to remove Antivirus 2009 (Uninstall Instructions) + How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo + How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller + Locky Ransomware Information, Help Guide, and FAQ Locky Ransomware Information, Help Guide, and FAQ + CryptoLocker Ransomware Information Guide and FAQ CryptoLocker Ransomware Information Guide and FAQ + CryptorBit and HowDecrypt Information Guide and FAQ CryptorBit and HowDecrypt Information Guide and FAQ + CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ * Tutorials + Latest + Popular + How to open a Windows 11 Command Prompt as Administrator How to open a Windows 11 Command Prompt as Administrator + How to make the Start menu full screen in Windows 10 How to make the Start menu full screen in Windows 10 + How to install the Microsoft Visual C++ 2015 Runtime How to install the Microsoft Visual C++ 2015 Runtime + How to open an elevated PowerShell Admin prompt in Windows 10 How to open an elevated PowerShell Admin prompt in Windows 10 + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * Forums * More + Startup Database + Uninstall Database + Glossary + Chat on Discord + Send us a Tip! + Welcome Guide * Home * News * Security * Okta's source code stolen after GitHub repositories hacked * * Okta's source code stolen after GitHub repositories hacked By Ax Sharma * December 21, 2022 * 01:15 AM * 0 okta Okta, a leading provider of authentication services and Identity and Access Management (IAM) solutions, says that its private GitHub repositories were hacked this month. According to a 'confidential' email notification sent by Okta and seen by BleepingComputer, the security incident involves threat actors stealing Okta's source code. Source code stolen, customer data not impacted BleepingComputer has obtained a 'confidential' security incident notification that Okta has been emailing to its 'security contacts' as of a few hours ago. We have confirmed that multiple sources, including IT admins, have been receiving this email notification. Earlier this month, GitHub alerted Okta of suspicious access to Okta's code repositories, states the notification. "Upon investigation, we have concluded that such access was used to copy Okta code repositories," writes David Bradbury, the company's Chief Security Officer (CSO) in the email. Despite stealing Okta's source code, attackers did not gain unauthorized access to the Okta service or customer data, says the company. Okta's "HIPAA, FedRAMP or DoD customers" remain unaffected as the company "does not rely on the confidentiality of its source code as a means to secure its services." As such, no customer action is needed. Okta security incident email sent December 2022Okta emails its 'security contacts' a security notification (BleepingComputer) At the time of writing our report, the incident appears to be relevant to Okta Workforce Identity Cloud (WIC) code repositories, but not Auth0 Customer Identity Cloud product, given the email wording. An excerpt from the remainder of the notification, reviewed by BleepingComputer, is published below: As soon as Okta learned of the possible suspicious access, we promptly placed temporary restrictions on access to Okta GitHub repositories and suspended all GitHub integrations with third-party applications. We have since reviewed all recent access to Okta software repositories hosted by GitHub to understand the scope of the exposure, reviewed all recent commits to Okta software repositories hosted with GitHub to validate the integrity of our code, and rotated GitHub credentials. We have also notified law enforcement. Additionally, we have taken steps to ensure that this code cannot be used to access company or customer environments. Okta does not anticipate any disruption to our business or our ability to service our customers as a result of this event. Note: The security event pertains to Okta Workforce Identity Cloud (WIC) code repositories. It does not pertain to any Auth0 (Customer Identity Cloud) products. We have decided to share this information consistent with our commitment to transparency and partnership with our customers. While ending its 'confidential' email that pledges a 'commitment to transparency,' Okta says it will publish a statement today on its blog. BleepingComputer reached out to Okta with questions in advance of publishing but a reply was not immediately available. Okta security incidents: year in review It's been a difficult year for Okta with its series of security incidents and bumpy disclosures. September this year, Okta-owned Auth0 disclosed a similar-style incident. According to the authentication service provider, older Auth0 source code repositories were obtained by a "third-party individual" from its environment via unknown means. But, Okta's problems began long before, amid the irregularity surrounding the disclosure of its January hack. March this year, data extortion group Lapsus$ claimed it had access to Okta's administrative consoles and customer data as it began posting screenshots of the stolen data on Telegram. After stating that it was investigating these claims, Okta shortly acknowledged that the hack being referred to had in fact occurred late January 2022 and potentially affected 2.5% of its customers. This figure was estimated to be roughly 375 organizations at the time, given Okta's 15,000+ customer base back then. The same week, Okta admitted that it had "made a mistake" in delaying the disclosure of this hack that, the firm said, had originated at its third-party contractor, Sitel (Sykes). In April, Okta clarified that the January breach had lasted "25 consecutive minutes" and the impact was significantly smaller than what was originally anticipated: limited to just two customers. Related Articles: GitHub to require all users to enable 2FA by the end of 2023 GitHub rolls out free secret scanning for all public repositories Okta shares fix for issue impacting Microsoft 365 SSO logins Microsoft sued for open-source piracy through GitHub Copilot Dropbox discloses breach after hacker stole 130 GitHub repositories * GitHub * Okta * Source Code * Theft * * * * * Ax Sharma Ax Sharma is a Security Researcher and Tech Reporter. His works and expert analyses have frequently been featured by leading media outlets including the BBC, Business Insider, Fortune, TechCrunch, The Register, and others. Ax's expertise lies in vulnerability research, malware analysis, and open source software. He's an active community member of British Association of Journalists (BAJ) and Canadian Association of Journalists (CAJ). Send any tips via email or Twitter DM. * Previous Article * Next Article Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] Popular Stories * Windows 10 Glass break Microsoft: KB5021233 causes blue screens with 0xc000021a errors * Apple Microsoft finds macOS bug that lets malware bypass security checks Follow us: * * * * Main Sections * News * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement Copyright @ 2003 - 2022 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT