Okta vishing is the new dodgy email: here’s how to guard against it

Social engineering campaigns evolve like any other form of attack, but sometimes the threat creeps up on you. Then bam: suddenly you realise itโ€™s a whole other level of risk to your organisation. Such is the case with what LevelBlue security researchers are calling Okta Vishing.

โ€œThis shift is redefining initial access, turning what was once an account compromise into an immediate data breach scenario,โ€ย said Jamie Mamroe, an Incident Responder at Cybereason, which was acquired by LevelBlue in November last year.

The shift Mamroe refers to is one that has seen attackers move away from phishing emails that target the inbox and towards voice calls impersonatingย IT support or an employee. But with one clear goal: compromising Single Sign-On.

โ€œIn many cases,โ€ Momroe warned, โ€œthis quickly leads to SharePoint and OneDrive data exfiltration, making this far more than just an authentication event.โ€™

If that sounds kind of scary, it should do, as it is. We are no longer talking about a single account compromise, but rather a potential full and immediate, organisationโ€‘wide, cloud data breach.

The LevelBlue report revealed that the Okta vishing attackers attempt to get the victim to:

  • Reset MFA
  • Enroll a new authenticator device
  • Provide one-time passcodes
  • Approve push notifications
  • Disclose passwords
  • Add attacker-controlled authentication methods
  • Reset Okta credentials
  • Provide password reset links
  • Disclose session cookies

And all while literally walking the target through the process over the phone.

Industry response to Okta vishing

โ€œThe initial attack vector here is still classic social engineering, however, the strategy has matured,โ€ said Mika Aalto, Co-Founder and CEO at Hoxhunt.

โ€œThe playbook resembles groups likeย Lapsus$,ย Scattered Spider, andย ShinyHunters, who used voice phishing to pressure help desks into resetting credentials or enrolling new authentication devices in breaches tied to platforms likeย Salesforce and Snowflake.โ€

The potential payload, Aalto concedes, makes these Okta vishing attacks both more efficient and significantly more damaging than traditional phishing campaigns.

โ€œDefending against these campaigns requires moving beyond awareness training to robust identity verification,โ€ said Jason Soroko, Senior Fellow at Sectigo. โ€œMandatory video verification and certificate-based authentication” should also be considered, he added.

Meanwhile, Okta has published a detailed threat advisory for customers regarding such attackers. โ€œIn a workplace context, there is no substitute for enforcing phishing resistance for access to resources,โ€ said Moussa Diallo, Threat Researcher at Okta Threat Intelligence. He added: โ€œWhen using Okta for workforce authentication, that would equate to enrolling users in Okta FastPass, passkeys or both for the sake of redundancy.โ€

Recent articles by Davey Winder, security expert

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.