Cyber Resilience

Okta (US)

Threat actors publicly named in connection with targeting Okta. Sorted by IDF score (rarity-weighted CVE attribution) with extraction confidence as tiebreaker. Each row's evidence is a verbatim quote from the source attribution.

3 attributed actor(s) · Category mix: criminal=2, unknown=1 · Attacker regions: International=2, —=1

Actor Category Sponsor Confidence Evidence CVEs IDF Last active
Scattered Spider (G1015)unknown0.90obtain administrator access in Okta, AWS, and Office 36511.22026
LAPSUS$ (G1004)criminal1.00Their victim list includes Microsoft, Okta, NVIDIA, Samsung, Uber,00.0
LAPSUS$ (persona) (HACK-LAPSUS-HACKTIVIST)criminal0.95claiming high-profile breaches at Microsoft, NVIDIA, Samsung, Okta00.0

Sibling victims

Other named victims whose attacker circle overlaps with this one — defenders use this to find sectoral or geographic cohorts that face the same actors.

« All victims  ·  All actors  ·  Browse by sector  ·  Recent breach notifications