Okta Support System Breach (Oct 2023): Session Tokens in Uploaded HAR Files
Retrospective: this article looks back at events from October 2023, written in 2026 with the benefit of hindsight.
In October 2023, Okta disclosed that an attacker had used stolen credentials to access its customer support case management system and view files uploaded by some customers as part of support cases. Several of those files were HTTP Archive (HAR) files containing session tokens.
What happened
Customers troubleshooting issues often upload HAR files — recordings of browser traffic — to support. HAR files can include cookies and session tokens. The attacker used tokens from these files to hijack sessions of Okta customers' administrators.
BeyondTrust, Cloudflare and 1Password each detected suspicious activity in their Okta environments and alerted Okta. BeyondTrust said it detected the activity in early October and reported it, but that Okta took about two weeks to confirm the breach.
Okta initially said about 1% of customers (134) were affected. In November 2023, it revised its findings: the attacker had downloaded a report containing names and email addresses of all customer support system users.
How the attacker got in
Okta said an employee had signed in to a personal Google profile on a company-managed laptop and saved credentials for a service account, which was likely compromised through the employee's personal Google account or device.
Why it mattered
- Support channels are a data exposure path. Files shared with vendors can contain live credentials.
- Identity provider breaches affect every downstream app.
- Customer detection found the breach before the vendor confirmed it.
Lessons in hindsight
- Sanitize HAR files before sharing; vendors should scrub them automatically.
- Bind sessions to devices so stolen tokens can't be replayed elsewhere.
- Short admin session lifetimes and re-authentication for sensitive actions.
- Monitor your identity provider's admin activity independently.
- How to Sanitize Support Uploads and Bind Tokens to Devices How-To & Hardening
- Detecting Session Token Theft HAR Files: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Your Identity Provider's Breach Is Your Breach CIO Briefings