HomeSecurityVishing campaign targets Okta SSO accounts for data theft

Vishing campaign targets Okta SSO accounts for data theft

Okta is sounding the alarm about a particularly sophisticated form of online fraud that combines phishing and voice social engineering (vishing). According to a recent report, custom phishing kits, specifically designed for phone-based attacks, with the aim of stealing Okta Single Sign-On (SSO) and, by extension, stealing sensitive corporate data from various other platforms.

Okta SSO

Phishing-as-a-Service and precision attacks

These tools are not stand-alone builds, but are sold as part of a “ phishing-as-a-service ” model. Multiple cybercriminal groups are already using them in active attacks, targeting major identity providers such as Google, Microsoft, and Okta , as well as cryptocurrency platforms .

See also: 1Password introduces new phishing prevention feature

Unlike classic static phishing pages, these new platforms act as an adversary-in-the-middle, allowing live interaction with the victim during a phone call. The content of the fake page changes in real time, following the rhythm and flow of the conversation.

Full control of the identification process

The critical advantage of these kits is complete control over the authentication process. As the victim enters username and password on the phishing page, the credentials are immediately transferred to the attacker. The attacker attempts to log in to the real service while remaining on the line with the victim.

When a multi-factor authentication (MFA) alert, such as a push notification or OTP code, appears, the kit dynamically adjusts the environment to make the request appear completely legitimate. The timing is so precise that even experienced users have difficulty detecting the fraud.

Targeted identification and fake helpdesks

Okta points out that these attacks are not random. The attackers conduct extensive reconnaissance, collecting information about the targeted employee, the applications they use, and their company's official IT support numbers.

See also: ESA: New breach exposes spacecraft and mission data

Vishing campaign targets Okta SSO accounts for data theft

They then call the victim pretending to be the internal helpdesk, using spoofed company numbers. Phishing pages often have names that refer to internal company services, such as “mycompany” or “internal,” reinforcing the illusion of legitimacy.

How to bypass modern MFA

Even advanced forms of MFA, such as number matching, can be bypassed. Attackers verbally instruct the victim which number to select, while the phishing kit displays the corresponding message in the browser.

For this reason, Okta recommends moving to phishing-resistant solutions, such as Okta FastPass, FIDO2 security keys, and passkeys, that don't rely on passwords or OTPs.

Okta SSO as a data “central gateway”

The severity of these attacks is due to Okta’s role as a centralized identity provider. Through SSO, an employee gains access to dozens of critical platforms, from Microsoft 365 and Google Workspace to Salesforce, Slack and Jira.

Once attackers gain access to the dashboard, they can identify applications with sensitive data and immediately begin extracting information, with Salesforce being a frequent target due to the ease of data extraction.

From violation to blackmail

Once the data theft is complete, extortion. The perpetrators send emails demanding payment to prevent the information from being made public. Some of these attacks are reportedly linked to the notorious ShinyHunters, although there is no official confirmation.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: FortiGate: Automated attacks change firewall settings

Vishing campaign targets Okta SSO accounts for data theft

According to information, attacks are actively continuing, with the main targets being companies in the fintech, wealth management, financial and advisory services sectors.

Okta's response and message to businesses

Okta emphasizes that protecting its customers is a top priority and that it is continuously detecting and dismantling phishing infrastructures. At the same time, it emphasizes the importance of educating employees and adopting modern security practices.

The message is clear: social engineering attacks are evolving rapidly and are now relying not only on technology, but also on persuasive human communication. For businesses, defense is no longer optional — it is essential.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS