← Incident database

okta-support-2023 · Disclosed 2023-10-20

Okta: support attachments enabled session hijacking

A compromised service account accessed support files. Session tokens in HAR attachments enabled hijacking of some customer sessions.

CredentialsEndpoint / session

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A support service account was abused to access attachments, including HAR files.

    [s1]Executive Summary
  • Assessment

    Credentials were saved in a personal Google account; compromise of that account or device was assessed as the most likely leak path.

    [s1]Executive Summary
  • Reported fact

    Okta reported session hijacking affecting five customers.

    [s1]Executive Summary

Timeline

  1. Start of the disclosed unauthorized access period. [s1]

  2. Service account disabled and associated sessions terminated. [s1]

  3. Incident disclosed. [s1]

Reported response

  • Reported fact

    Personal Chrome profile sign-in was restricted and monitoring strengthened.

    [s1]Remediation Tasks

Evidence relevant to prevention

Operational controls to inspect

Support attachments are a credential exposure path. Inspect sanitization and revocation of exposed sessions.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited primary sources do not establish AI involvement. This does not establish that AI was absent.

The precise credential leak path remains an assessment in the cited root-cause report.

Sources

  1. [s1] Okta · Primary source

    Unauthorized Access to Okta Support: Root Cause and Remediation ↗

    Published 2023-11-03 · Reviewed 2026-10-02