Okta reported a spike in credential-stuffing activity against user accounts from April 19 through April 26, 2024. The company said the attacks it observed used anonymizing services, including residential proxies, but did not publish a total request count or affected-account figure. This is a report about activity observed in 2024, not evidence that the same spike is happening now. For administrators, the practical response is to investigate authentication logs for both failures and successful sign-ins, then strengthen controls against reused passwords and risky sign-ins.
What Okta reported
In an April 27, 2024 post, Okta’s Identity Threat Research team described a spike in credential-stuffing activity observed from April 19 to April 26. The post says the activity appeared to share infrastructure and relied on anonymizing services, including TOR and residential proxy services. Requests routed this way may appear to come from ordinary mobile devices and browsers rather than familiar virtual private server ranges. These details describe Okta’s observations; they do not identify who operated the campaigns.
Okta wrote: “All recent attacks we have observed share one feature in common: they rely on requests being routed through anonymizing services such as TOR.” The statement is scoped to the attacks Okta observed. The post gives the observation window but no total request volume, affected-account count, or comparison baseline, so “spike” should not be converted into an invented percentage or total. Okta’s April 27, 2024 threat-intelligence post lists Moussa Diallo, Senior Manager, Identity Threat Research, and Brett Winterford, VP, Okta Threat Intelligence, as authors.
What credential stuffing is—and why it works
Credential stuffing is automated testing of username-and-password combinations exposed in earlier breaches, phishing, or malware campaigns against a different service. It differs from guessing one person’s password from scratch: attackers start with credentials already associated with real users, then try them elsewhere. The attack can succeed when someone has reused a password across services. Okta’s credential-stuffing explainer describes the technique and its relationship to password reuse.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How to tell if an Okta tenant is being targeted
Review Workforce Identity system logs
Okta’s April guidance directs administrators to relevant system-log detections, including “Suspected Credential Stuffing Attack (T1110.004).” Investigate failed logins, password-spray events, and targeted brute-force activity alongside that detection. A rise in failures is a reason to investigate, not proof that an account was compromised: establish whether any attempts succeeded and which accounts or configurations may need remediation.
Check Customer Identity Cloud cross-origin events
For Customer Identity Cloud tenants that use cross-origin authentication, Okta recommends reviewing these event types:
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
fcoa: failed cross-origin authentication.scoa: successful cross-origin authentication.pwd_leak: a password-leak event.
Okta’s Customer Identity Cloud post says suspicious activity began April 15, 2024, but does not say it was continuous for every tenant. Unexpected cross-origin events, a sudden rise in successful cross-origin events, or a rising failure-to-success ratio may indicate targeting. Investigate whether the activity is expected for your application and tenant; if credentials were compromised, Okta recommends rotating them immediately. See Okta’s Customer Identity Cloud guidance.
How to reduce credential-stuffing and account-takeover risk
Okta’s recommendations combine controls that limit automated attempts with authentication methods that make stolen passwords less useful. Their effectiveness, user friction, recovery implications, and availability vary by product and configuration; the cited sources do not provide a quantitative head-to-head test.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Control | What it helps with | Trade-off or implementation point |
|---|---|---|
| ThreatInsight in log-and-enforce mode | Okta says ThreatInsight can block requests from IP addresses involved in large-scale credential attacks before authentication. | Okta attributed cases where suspicious requests proceeded to authentication to a small percentage of customers with a combination of Classic Engine, ThreatInsight in Audit-only mode, and policies that permitted anonymizing proxies. Okta says customers using Identity Engine with ThreatInsight in log-and-enforce mode and denying access from anonymizing proxies were protected from the opportunistic attacks described in its post. This is Okta’s account of that observed activity, not a guarantee about every attack. |
| Restrictions on anonymizing proxies | Can deny sign-ins routed through anonymizing services, one type of infrastructure Okta observed. | Assess legitimate user and application needs before restricting access; the post does not quantify the resulting user impact. |
| CAPTCHA for risky sign-ins | Adds a challenge to sign-ins judged risky, helping distinguish automated attempts. | Introduces user friction. Okta recommends evaluating CAPTCHA challenges as part of layered defenses. |
| MFA | Adds a factor beyond the password, reducing the value of a reused password by itself. | Consider the sign-in experience and account-recovery path as well as enrollment and enforcement. |
| Passkeys and passwordless authentication | Okta identifies passkeys as its preferred longer-term, phishing-resistant option; they do not depend on users entering a reusable password at sign-in. | Plan for user enrollment, supported authenticators, and recovery. Okta recommends passkeys generally; its cited guidance does not require a particular hardware key. |
| Strong password policies and breached-password detection | Can make weak or already exposed passwords harder to use successfully. | These are among Okta’s Customer Identity Cloud recommendations; verify availability for your product edition and tenant. |
Okta’s separate Customer Identity Cloud advice also says to restrict permitted origins when cross-origin authentication is necessary and disable the feature when it is not used. Review edition and plan eligibility before relying on any feature, since availability may depend on the product configuration. Okta’s May 2024 defense guidance discusses protections including password policies, breached-password detection, origin restrictions, and disabling unused cross-origin authentication.
A practical investigation sequence
- Check threat detections and sign-in patterns. Review the Okta system-log detection for suspected credential stuffing, then examine failed logins, password-spray events, and targeted brute-force activity.
- Look for successful access, not just blocked attempts. Identify accounts with successful sign-ins that coincide with suspicious activity and check whether the locations, devices, or application behavior are expected.
- For Customer Identity Cloud cross-origin flows, compare event types. Review
fcoa,scoa, andpwd_leakevents, and investigate unexpected events or changes in the failure-to-success pattern. - Contain confirmed credential exposure. Rotate compromised credentials immediately, then assess affected accounts and configurations for remediation.
- Review preventive settings. Evaluate ThreatInsight enforcement, anonymizer restrictions, CAPTCHA for risky sign-ins, MFA or passkeys, and the origin and usage settings for cross-origin authentication.
What the 2024 report does—and does not—show
Okta’s public posts establish an observed activity window and describe the infrastructure and defenses relevant to that activity. They do not publish a named threat actor, a total number of requests, an affected-account total, or evidence that the same spike continues in 2026. Treat the report as a dated warning and a useful guide to controls and log signals, not as a current incident alert.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

