Okta said that for 25 minutes on January 21, Lapsus$ “actively controlled” a workstation used by a support engineer at third-party company Sitel.
“The threat actor was unable to authenticate directly to any Okta accounts,” said Okta, which initially took two months to inform customers of the incident.