Okta reports stolen source code

December 22, 2022

Okta, the access management and identity provider, said that an attacker gained illegal entry to its private GitHub repositories and replicated some of its source code. It had earlier begun notifying customers via email of an incident in which an unidentified party stole the company’s source code.

This is the second security incident of the year. The most recent came to life when Okta was notified by GitHub in early December of possible suspicious access to its online code repositories. Okta determined after an investigation that someone had used that access to copy over its source code but had not gained unauthorized access to its identity and access management systems.

“Our investigation concluded that there was no unauthorized access to the Okta service, and no unauthorized access to customer data,” company officials said in a statement. “Okta does not rely on the confidentiality of its source code for the security of its services. The Okta service remains fully operational and secure.”

According to the statement, the copied source code only applies to the Okta Workforce Identity Cloud and not to any Auth0 products used with the company’s Customer Identity Cloud. Okta officials also stated that after learning of the breach, they temporarily restricted access to the company’s GitHub repositories and suspended GitHub integrations with third-party apps.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

May 20, 2026 The Cybersecurity and Infrastructure Security Agency, the arm of the U.S. government tasked with protecting critical infrastructure more...

May 11, 2026 Instructure has restored access to its Canvas learning platform after a cyberattack disrupted service for universities and more...

May 6, 2026 The official White House mobile app for iOS and Android is facing scrutiny after a security researcher more...

May 4, 2026 Microsoft Defender mistakenly detected legitimate DigiCert root certificates as malware, triggering widespread false-positive alerts and, in some more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn