Lapsus$ Breached Okta Using Spreadsheet Of Passwords

Share post:

Lapsus$ was able to infiltrate Okta’s internal system after accessing a spreadsheet of passwords on compromised Sitel’s internal network.

Sitel discovered the security incident in its VPN gateways on a legacy network belonging to Sykes, a customer service company working for Okta and acquired by Sitel in 2021.

The attackers used remote access services and publicly accessible hacking tools to compromise and navigate through Sitel’s network.

After gaining deeper visibility into the network, the hackers were able to gain access to a spreadsheet on Sitel’s internal network called “DomAdmins-LastPass.xlsx.”

The spreadsheet file contained passwords for domain administrator accounts that were exported from a Sitel employee’s LastPass password manager.

The hackers created a new Sykes user account that gives them broad access to the organization and helps keep them within the system in case they were discovered and locked out.

For more information, read the original story in TechCrunch.

SUBSCRIBE NOW

Related articles

US Bank Regulator Hacked – Sensitive Banking Info Stolen

The US Office of the Comptroller of the Currency (OCC) reported a cybersecurity breach involving unauthorized access to...

Apple Flew In iPhone Shipments to Mitigate Impact of New Tariffs

In response to impending tariffs imposed by the U.S. government, Apple has reportedly airlifted five cargo planes filled...

Social Security Website Crashes Linked to DOGE Software Update

The Social Security Administration (SSA) has experienced multiple website outages in recent weeks, disrupting services for beneficiaries. These...

IDC Reports Tariffs Could Cut IT Spending Growth In Half

The International Data Corporation (IDC) has cautioned that the U.S. government's recent tariffs may slash predicted global IT...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways