Hackers steal Okta source code via GitHub repositories
In an email, Okta informed customers of an incident in which code was stolen from the login provider’s GitHub repositories. According to the company, no customer data was stolen and hackers had no access to Okta’s systems.
Okta sent the email to IT administrators of its customers. The email has been viewed by BleepingComputer. Okta writes that GitHub contacted the company in early December 2022 to inform it of possible unauthorized access to Okta’s repositories. Company confirms that code has indeed been stolen.
According to the login provider, this is code from the Okta Workforce Identity Cloud. The company emphasizes that the hackers did not have access to Auth0’s code, which is used with the company’s Customer Identity Cloud. Further says a spokesperson for Okta told Engadget that “the stolen code does not impact the security of the company’s products because security is not dependent on the source code being secret.”
It is the second time this year that Okta has been targeted by hackers. In January, hackers from the Lapsus$ group penetrated the security company. The damage was then considerably greater because the hackers were able to penetrate two other companies via Okta. The hackers also had access to Okta’s Slack and Jira environments themselves.