okta-support-2023 · Disclosed 2023-10-20
Okta: support attachments enabled session hijacking
A compromised service account accessed support files. Session tokens in HAR attachments enabled hijacking of some customer sessions.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
A support service account was abused to access attachments, including HAR files.
[s1]Executive Summary - Assessment
Credentials were saved in a personal Google account; compromise of that account or device was assessed as the most likely leak path.
[s1]Executive Summary - Reported fact
Okta reported session hijacking affecting five customers.
[s1]Executive Summary
Timeline
Reported response
- Reported fact
Personal Chrome profile sign-in was restricted and monitoring strengthened.
[s1]Remediation Tasks
Evidence relevant to prevention
Operational controls to inspect
Support attachments are a credential exposure path. Inspect sanitization and revocation of exposed sessions.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited primary sources do not establish AI involvement. This does not establish that AI was absent.
The precise credential leak path remains an assessment in the cited root-cause report.
Sources
[s1] Okta · Primary source
Unauthorized Access to Okta Support: Root Cause and Remediation ↗Published 2023-11-03 · Reviewed 2026-10-02