Vishing attacks on Okta identity systems have increased in which attackers simply call the victim or an IT help desk and convince them to weaken or reset multi-factor authentication (MFA).In an April 13 blog post, LevelBlue researchers said once Okta is compromised via vishing, the attackers gain access to an enterprise’s SaaS systems via single sign-on (SSO), which leads to the exfiltration of SharePoint, OneDrive, Salesforce, and Google Workspace data.The LevelBlue researchers explained that as part of the attack, the threat actors aim to get the victim or help desk to reset MFA, enroll a new authenticator device, provide one-time passcodes, disclose passwords, or reset Okta credentials.“The initial attack vector here is still classic social engineering, however, the strategy has matured,” said Mika Aalto, co-founder and CEO at Hoxhunt. “Instead of targeting individual users, attackers are moving upstream to bypass MFA at the identity provider level, manipulating in this case Okta's IT help desk to unlock access across the targeted organization.”Aalto said the playbook resembles groups such as Lapsus$, Scattered Spider, and ShinyHunters, threat actors that have used vishing to pressure help desks into resetting credentials or enrolling new authentication devices in breaches tied to platforms like Salesforce and Snowflake.“Attackers are thinking: why break into a single account when we can go after the systems that create and manage identity,” said Aalto. “Instead of breaking a window or stealing a spare key, they’re targeting the locksmith. If they gain control of an identity provider or help desk workflow, they can effectively generate a master key that unlocks many systems across the organization.”Denis Calderone, Principal-CTO at Suzu Labs, added that vishing gets the headlines right now, but it's one of several ways attackers get past MFA and into identity providers: phishing kits that proxy real login pages in real time, help desk manipulation through live chat and ticketing systems, clipboard theft through fake CAPTCHA pages, even credentials pulled from old infostealer logs.“We've been advising clients on all of these just in the past few weeks,” said Calderone. “This isn't a vishing problem. It's a centralized access problem. Compromise any enterprise SSO provider and you inherit its trust into M365, Salesforce, Slack, the VPN, and everything else wired through SSO. One login opens a lot of doors. The social engineering is simple. The architecture makes it devastating.”Rogier Fischer, co-founder and CEO of Hadrian, said security teams often forget that people are one of the most persistent parts of the attack surface. Years of phishing training have made employees more cautious about email, but Fischer said that’s why attackers have moved beyond it.“We’ve already seen this shift with smishing, where phishing tactics moved to SMS and caught users off guard because they weren’t expecting attacks there,” said Fischer. “Vishing is simply the next evolution. The core technique hasn’t changed — it’s still about manipulation and trust — but the delivery channel has, and that’s enough to bypass the mental defenses people have built.”Rogier added that when someone hears a voice that sounds like a colleague or senior executive, the instinct is to trust, not verify.“Add AI in the mix, and attackers can now easily deepfake people’s voices using publicly available recordings,” said Fischer. “For high-profile individuals, there’s often more than enough data available to make these impersonations highly believable.”Jason Soroko, senior fellow at Sectigo, said the rise of Okta vishing exposes a fundamental structural weakness in modern cloud architectures, not just a triumph of social engineering. Centralized identity providers consolidate authentication into a single access point for convenience, said Soroko, but that same design transforms a localized compromise into a systemic breach.“Attackers are simultaneously exploiting the inherent trust in IT support workflows and the absence of cryptographic verification during human interactions,” said Soroko. “Whether attackers call in to the help desk posing as locked-out users or impersonate IT staff reaching a tired employee, they weaponize the very mechanisms intended to keep the business running. Defending against these campaigns requires moving beyond awareness training to robust identity verification.”
Identity, SSO/MFA, IAM Technologies, Ransomware, Phishing

Vishing attacks on Okta identity systems on the rise

(Adobe Stock)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



