// Service

Okta

Workforce and customer identity provider.

// Alerts

Recent threats

// OktaCRITICAL

ShinyHunters used voice-phishing (vishing) to compromise Okta SSO credentials at McKesson Corporation, then pivoted to Snowflake and Salesforce to steal approximately 284 million patient records including names, SSNs, dates of birth, medical information, and Medicaid numbers between August 21–25, 2026. McKesson confirmed the breach on August 28. The group demanded $55.2 million ransom and has executed similar Okta-to-cloud-data attacks against multiple organizations in 2026, establishing a pattern where compromised SSO credentials enable large-scale data exfiltration.

ShinyHunters extortion group is actively targeting healthcare organizations in a vishing campaign to reset Okta SSO credentials and MFA. Attackers impersonate employees to trick help desks into performing password resets, granting legitimate access to Okta accounts and downstream cloud platforms like Microsoft 365 and SharePoint for data exfiltration. Health-ISAC issued a major advisory on July 24, 2026 warning of this attack pattern.

Google's Threat Intelligence Group is tracking UNC6671, a cybercrime group conducting voice phishing attacks to hijack Okta accounts and exfiltrate corporate data for extortion. Attackers impersonate internal IT helpdesk staff, directing victims to adversary-in-the-middle phishing sites that capture credentials and MFA tokens. Since July 2026, the group has prioritized financial services, private equity, law firms, and rating agencies. Multiple campaigns share infrastructure under brand names including Falcon, Helix, Pink, and Redact.

// OktaMEDIUM

Okta Red Team disclosed HollowByte, a denial-of-service vulnerability in OpenSSL triggered by 11-byte malicious TLS handshake headers. The flaw causes memory exhaustion and heap fragmentation on glibc systems; unpatched servers can have significant RAM locked up by a single attacker. OpenSSL patched the issue in June 2026 releases without assigning a CVE or formal advisory, complicating discovery and deployment tracking.

// OktaMEDIUM

Okta has issued a security advisory warning organizations of an ongoing vishing campaign exploiting Microsoft 365 users. The threat actor, tracked as O-UNC-066 (also known as Pink/CL-CRI-1147), has been conducting voice-enabled attacks since April 2026 to harvest Microsoft Entra ID credentials. Attackers direct victims to fake passkey enrollment pages designed to mimic legitimate Microsoft interfaces. Multiple sectors including automotive, aviation, healthcare, and technology have been targeted, primarily for data extortion purposes.