kurtseifried,

Did anyone else get this #phishing email claiming to be from Okta? csid.com, they redirect it to Experian to make it look legitimate? Looks like I'm not the only one https://news.ycombinator.com/item?id=38714897 also @briankrebs for visibility.

chort,

deleted_by_author

kurtseifried,

@chort @briankrebs they could have branded it as okta better (eg csid.com took a while to track down). Linked to an official page on okta.com and so on.

briankrebs,

@kurtseifried It reads like the notifications that Okta said it had already made to all affected customers when I broke the story about their most recent incident.

https://krebsonsecurity.com/2023/10/hackers-stole-access-tokens-from-oktas-support-unit/

Update, 2:57 p.m. ET: Okta has published a blog post about this incident that includes some “indicators of compromise” that customers can use to see if they were affected. But the company stressed that “all customers who were impacted by this have been notified. If you’re an Okta customer and you have not been contacted with another message or method, there is no impact to your Okta environment or your support tickets.”

To me, the more concerning part is that Experian appears to be the messenger.

kurtseifried,

@briankrebs right? We were an Okta customer ages ago, but left them well before this happened. I’d like to think they got explained involved because that’s what the lawyers they’ve hired to handle this breach recommended maybe? But the whole thing seems really weird right now.

merospit,

@kurtseifried @briankrebs I received one. Thought it may have been phishing until another team member received one.

kurtseifried,

@merospit @briankrebs using the metric of everybody got one of these is not a good way to assign a safety rating to something.

kurtseifried,

Original Message
Message ID <1531460072.29729015.1703124342154@marketing.csid.com>
Created at: Wed, Dec 20, 2023 at 7:05 PM (Delivered after 0 seconds)
From: Okta <okta@mail.csid.com>
To: "kseifried@cloudsecurityalliance.org" <kseifried@cloudsecurityalliance.org>
Subject: Okta October Security Incident – Contact Information Exposure
SPF: PASS with IP 96.46.132.207 Learn more
DKIM: 'PASS' with domain mail.csid.com Learn more
DMARC: 'PASS' Learn more

kurtseifried,

Oh wow. this is apparently legitimate, "CSIdentity Corporation" which got glomed by Experian in 2016 https://www.experian.com/blogs/news/2016/04/18/csid/ (finally found a link to csid.com from an Experian site)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • tacticalgear
  • JUstTest
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • megavids
  • lostlight
  • All magazines