Security

Okta’s latest hack fallout hits Cloudflare, 1Password

Comment

Okta logo on the front of its office in San Francisco
Image Credits: Michael Vi / Getty Images

Network and security giant Cloudflare and password manager maker 1Password said hackers briefly targeted their systems following a recent breach of Okta’s support unit.

Both Cloudflare and 1Password said their recent intrusions were linked to the Okta breach, but that the incidents did not affect their customer systems or user data.

“We immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing,” said 1Password chief technology officer Pedro Canahuati in a blog post. “We’ve confirmed that this was a result of Okta’s support system breach,” said Canahuati.

Ars Technica first reported that 1Password was affected by Okta’s breach.

Okta, which provides single sign-on technology to companies and organizations, said late on Friday that hackers had broken into its customer support unit and stole files uploaded by its customers for diagnosing technical problems. These files include browser recording sessions that can contain sensitive user credentials, such as cookies and session tokens, which if stolen can allow hackers to impersonate user accounts.

Okta spokesperson Vitor De Souza told TechCrunch that about 1% of its 17,000 corporate customers — or 170 organizations — were affected by its breach.

In an attached report detailing the security incident, 1Password said the hackers used a session token from a file that had been uploaded by a member of the IT team earlier in the day to Okta’s support unit system for troubleshooting. The session token allowed the hackers to use the IT member’s account without needing their password or two-factor code, granting the hacker limited access to 1Password’s Okta dashboard.

1Password said the incident occurred on September 29, two weeks before Okta went public with details of the incident.

Cloudflare also confirmed in a blog post on Friday that hackers similarly targeted its systems using a session token stolen from Okta’s support unit. Cloudflare’s chief information security officer Grant Bourzikas said Cloudflare’s incident, which began on October 18, resulted in “no access from the threat actor to any of our systems or data,” in large part because Cloudflare uses hardware security keys that evade phishing attacks.

Security company BeyondTrust said it was also affected by Okta’s breach, but that it also quickly shut down its intrusion. In a blog post, BeyondTrust said it notified Okta of the incident on October 2, but accused Okta of not acknowledging the breach for almost three weeks.

This is Okta’s latest security incident, following the theft of some of its source code in December 2022, and an incident earlier in January 2022 where hackers posted screenshots of Okta’s internal network.

Okta’s stock price dropped more than 11% on Friday — wiping at least $2 billion off the company’s value — following news of the breach, which was first reported by security journalist Brian Krebs.

Okta says hackers stole customer access tokens from support unit

More TechCrunch

Listen, I’m tired of talking about Boeing’s Starliner, too, but the spacecraft still isn’t home and questions are mounting about NASA’s transparency.

TechCrunch Space: I’m tired of talking about Starliner, too

Saudi Arabia is committing even more money to Lucid Motors as the EV startup struggles to erase its losses. Lucid announced Monday as part of its second-quarter earnings report that…

Lucid pumps $1.5B from Saudi wealth fund after CEO warned relying on its ‘bottomless wealth’ was ‘dangerous’

Google will appeal a U.S. District Court judge’s opinion Monday that found the technology giant acted illegally to maintain a monopoly in online search. The decision from Judge Amit P.…

Google loses massive antitrust case over search, will appeal ruling

Last year, OpenAI held a splashy press event in San Francisco during which the company announced a bevy of new products and tools, including the ill-fated App Store-like GPT Store.…

OpenAI tempers expectations with less bombastic, GPT-5-less DevDay this fall

Muon Space closed a new tranche of funding for its space-as-a-service business.

Muon Space closes $56M to scale all-in-one satellite platform

We’re so excited to announce that we’ve added a dedicated AI Stage presented by Google Cloud to TechCrunch Disrupt 2024. It joins Fintech, SaaS and Space as the other industry-focused…

Announcing the agenda for the AI Stage at TechCrunch Disrupt 2024

A startup developing AI market research based on location data, and backed by a who’s who, has quietly raised, TechCrunch has learned.

Placer.ai boosts valuation to $1.5B after quietly raising another $75M

Safari’s newest feature, Distraction Control, can remove distracting elements from a website. The feature follows Browser Company’s Arc Browse’s addition of Boosts last year, which similarly lets users remove features…

Apple’s new Safari feature removes distracting items from websites

By collecting this data, OpenAI “profited significantly” from the creators’ work, the complaint alleges.

YouTuber files class action suit over OpenAI’s scrape of creators’ transcripts

India’s fast-growing quick commerce market is getting a new deep-pocketed entrant: Walmart-owned Flipkart, India’s largest e-commerce firm. Flipkart has started to roll out Flipkart Minutes, its quick commerce service, in…

Flipkart blitzes into India’s 10-minute quick commerce battle

The list includes Elon Musk’s xAI, which is already valued at a staggering $24 billion, as well as a good number of other AI startups.

38 startups have become unicorns so far in 2024: Here’s the full list

When a company is the size of Amazon, a lot of bad actors will come after it and its customers, which makes defending the network a monster job. Over the…

AWS unveils Mithra to identify and mitigate malicious domains across its massive system

The European Commission has closed a Digital Services Act (DSA) investigation of a rewards feature in TikTok Lite by accepting commitments from the social media giant to permanently withdraw the…

TikTok Lite: EU closes addictive design case after TikTok commits to not bring back rewards mechanism

Groq, a startup developing chips to run generative AI models faster than conventional processors, said on Monday that it has raised $640 million in a new funding round led by…

AI chip startup Groq lands $640M to challenge Nvidia

COVID-19 pushed people to take up outdoor activities. Now, startups are helping companies and consumers keep up with demand.

From golf to hunting, a new crop of startups want to make these experiences even better

Despite increasing demand for AI safety and accountability, today’s tests and benchmarks may fall short, according to a new report. Generative AI models — models that can analyze and output…

Many safety evaluations for AI models have significant limitations

OpenAI has built a tool that could potentially catch students who cheat by asking ChatGPT to write their assignments — but according to The Wall Street Journal, the company is…

OpenAI says it’s taking a ‘deliberate approach’ to releasing tools that can detect writing from ChatGPT

Chief Product Officer Craig Saldanha says AI is already transforming the Yelp experience.

Yelp’s chief product officer talks AI and authenticity

Featured Article

Even after $1.6B in VC money, the lab-grown meat industry is facing ‘massive’ issues

Any goal that puts cultivated meat in big box grocery stores or on fast food menus in the 2020s is “unrealistic,” according to experts.

Even after $1.6B in VC money, the lab-grown meat industry is facing ‘massive’ issues

Warren Buffett’s Berkshire Hathaway cut its Apple holding by around half, to $84.2 billion, according to an SEC filing. While Apple remains the firm’s largest stock holding by far, Buffett…

Warren Buffett’s Berkshire Hathaway sells half its Apple stock

A fireside chat between Jensen Huang and Mark Zuckerberg at SIGGRAPH 2024 took some unexpected turns. What started as a conversation about the capabilities of Nvidia GPUs and Zuckerberg’s vision…

Zuckerberg and Jensen show off their friendship, while an AI necklace covets yours

We spoke to Harness CEO and founder Jyoti Bansal about his previous company, which Cisco bought for $3.7 billion in 2017.

When a big company comes after a hot startup, it’s not a slam dunk decision to sell

Dojo is Tesla’s custom-built supercomputer that’s designed to train its “Full Self-Driving” neural networks.

Tesla Dojo: Elon Musk’s big plan to build an AI supercomputer, explained

Featured Article

Trade My Spin is building a business around used Peloton equipment

Trade My Spin has pieced together a logistics network capable of offering same or next day delivery in most major cities in the continental U.S.

Trade My Spin is building a business around used Peloton equipment

Featured Article

Meet the founder who built and sold a $600M enterprise software startup from Sri Lanka

Sanjiva Weerawarana co-founded WSO2 in 2005, recently selling it for more than $600M. He sometimes drives for Uber, too.

Meet the founder who built and sold a $600M enterprise software startup from Sri Lanka

Investors are assisting startup founders earlier than ever in an effort to help them bridge the first climate tech valley of death.

Why Bill Gates’ Breakthrough Energy and other investors are scouring universities for founders

While both the DSA and DMA aim to achieve distinct things, they are best understood as a joint response to Big Tech’s market power.

DSA vs. DMA: How Europe’s twin digital regulations are hitting Big Tech

Featured Article

How the theft of 40M UK voter register records was entirely preventable

A scathing rebuke by the U.K. data protection watchdog reveals what led to the compromise of tens of millions of U.K. voters’ information.

How the theft of 40M UK voter register records was entirely preventable

Self-driving technology company Aurora Innovation was hoping to raise hundreds of millions in additional capital as it races toward a driverless commercial launch by the end of 2024. The company, which…

Self-driving truck startup Aurora Innovation raises $483M in share sale ahead of commercial launch

The U.S. Federal Trade Commission and the Justice Department are suing TikTok and ByteDance, TikTok’s parent company, with violating the Children’s Online Privacy Protection Act (COPPA). The law requires digital…

FTC and Justice Department sue TikTok over alleged child privacy violations