Okta support compromise: support artefacts can contain session power
Files uploaded to support for troubleshooting contained enough to hijack sessions.
Nobody thought of a support ticket as a place holding credentials, but diagnostic exports frequently contain tokens, cookies and configuration that are as good as a login. Support systems are usually outside the security perimeter people imagine, and the artefacts inside them deserve the same handling as the systems they describe.
More on Real incident lessons
- Equifax: knowing about a vulnerability is not knowing it is patchedThe list said five
- Target: supplier access showed why third-party portals need strong segmentation from sensitive systemsThe partitions stop short
- Colonial Pipeline: business shutdown can follow IT compromiseNothing touched the pipe
- Help-desk identity processes are attack surfaces when social engineering can trigger password resets or MFA transferThree answers, and it moves
- British Library: recovery can outlast initial disruptionThe outage was the short part
- Hawaii false missile alert: test and live alert paths need separation because confirmation prompts cannot correct a convinced operatorA hand apart
