Okta is warning of a dramatic increase in credential stuffing attacks targeting its identity and access. Some of these attacks are successful, with customer accounts being compromised.

In credential stuffing attacks, attackers leverage automated tools to attempt millions of logins using a list of username/password pairs that have been leaked online from past breaches. The technique is particularly effective when users reuse the same login information across multiple platforms.
According to Okta, the attacks observed appear to originate from the same infrastructure used in brute-force and password-spraying attacks previously reported by Cisco Talos.
See also: Roku: 576,000 accounts compromised through credential stuffing
In all attacks observed by Okta, requests originated through the TOR anonymization network and various residential proxies.
Okta: Impact of credential stuffing attacks and protection
Okta says that many of the attacks were successful, especially against organizations using the Okta Classic Engine with ThreatInsight configured in Audit-only mode rather than Log and Enforce mode.
Similarly, organizations that don't block access from anonymizing proxies are at greater risk. However, Okta said the attacks were successful for a small percentage of customers.
See also: Chrome “Device Bound Session Credentials”: Hackers will not be able to use stolen cookies
The company lists some tips for blocking these attacks:
- Setting ThreatInsight to Log and Enforce Mode to block IP addresses that have been linked to credential stuffing attacks.
- Denial of access from anonymizing proxies to proactively block requests originating from suspicious anonymizing services.
- Switch to Okta Identity Engine, which offers more robust security features.
- Implement Dynamic Zones that allow organizations to block or allow specific IPs and manage access based on geographic location and other criteria.
See also: PetSmart: Warns customers about credential stuffing attack

More general tips against account hacking include:
- Use strong passwords ( which means they consist of letters, symbols, and numbers).
- Use different passwords for different servicesso that all accounts cannot be accessed if one password is leaked.
- Implement multi-factor authentication. This means that even if someone has your username and password, they'll need a second factor – usually a code sent to your phone – to gain access.
- Reject requests outside of company sites, block IP addresses with bad reputation, monitor and respond to suspicious connections.
- Regularly monitor accounts for any suspicious activity. If you notice anything unusual, change your password immediately and contact your service.
Source: www.bleepingcomputer.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
