Identity and access management company Okta has issued a warning about social engineering attacks targeting IT service desk agents at United States-based customers, with the aim of tricking them into reinstating multi-factor authentication (MFA) for highly privileged users.
See also: Germany: Financial regulator affected by DDoS attack

See also: Pizza Hut Australia: Hacked by ShinyHunters group
The attackers' goal was to compromise highly privileged Okta Super Administrator accounts to gain access and abuse identity federation features that allowed for the impersonation of users from the compromised organization.
Okta provided breach indications for attacks detected from July 29 to August 19.
The company says that before calling a target organization's IT services office, the attacker either had passwords for privileged accounts or was able to compromise the authentication flow through Active Directory (AD).
After a successful breach of a Super Admin account, the perpetrator turned to anonymizing proxy services, a new IP address , and a new device.
The hackers used their administrative (admin) access to elevate the privileges of other accounts, resetting enrolled authenticators and also removing two-factor authentication (2FA) for some accounts.
Using the source IdP, the hackers modified the usernames to match the actual users on the compromised target IdP. This allowed them to impersonate the targeted user and gain access to applications that use the Single-Sign-On (SSO) authentication mechanism.
See also: Suffolk High School: Offline after cyberattack

To protect administrator accounts from external actors, Okta recommends the following security measures:
- Enforce phishing- resistant authentication using Okta FastPass and FIDO2 WebAuthn.
- Re-authentication is required for privileged access to applications, including the Admin Console.
- Use strong authentication for self-service recovery and restriction to trusted networks.
- Improve Streamline Remote Management and Monitoring (RMM) tools and exclude unauthorized ones.
- Improve help desk verification with visual checks, MFA challenges, and admin approvals.
- Enable and test notifications for new devices and suspicious activity.
- Limit Super Administrator roles, implement privileged access management, and delegate high-risk tasks.
- Authorize administrators to log in from managed devices with phishing and restrict access to trusted zones.
Okta's guide includes additional breach indicators, such as system log events and workflow templates that show malicious activity at various stages of the attack. The company also provides a list of IP addresses associated with attacks observed from June 29 to August 19.
Information source: bleepingcomputer.com
