Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Okta reported a spike in credential-stuffing activity against user accounts from April 19 through April 26, 2024. The company said the attacks it observed used anonymizing services, including residential proxies, but did not publish a total request count or affected-account figure. This is a report about activity observed in 2024, not evidence that the same spike is happening now. For administrators, the practical response is to investigate authentication logs for both failures and successful sign-ins, then strengthen controls against reused passwords and risky sign-ins.

What Okta reported

In an April 27, 2024 post, Okta’s Identity Threat Research team described a spike in credential-stuffing activity observed from April 19 to April 26. The post says the activity appeared to share infrastructure and relied on anonymizing services, including TOR and residential proxy services. Requests routed this way may appear to come from ordinary mobile devices and browsers rather than familiar virtual private server ranges. These details describe Okta’s observations; they do not identify who operated the campaigns.

Okta wrote: “All recent attacks we have observed share one feature in common: they rely on requests being routed through anonymizing services such as TOR.” The statement is scoped to the attacks Okta observed. The post gives the observation window but no total request volume, affected-account count, or comparison baseline, so “spike” should not be converted into an invented percentage or total. Okta’s April 27, 2024 threat-intelligence post lists Moussa Diallo, Senior Manager, Identity Threat Research, and Brett Winterford, VP, Okta Threat Intelligence, as authors.

What credential stuffing is—and why it works

Credential stuffing is automated testing of username-and-password combinations exposed in earlier breaches, phishing, or malware campaigns against a different service. It differs from guessing one person’s password from scratch: attackers start with credentials already associated with real users, then try them elsewhere. The attack can succeed when someone has reused a password across services. Okta’s credential-stuffing explainer describes the technique and its relationship to password reuse.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How to tell if an Okta tenant is being targeted

Review Workforce Identity system logs

Okta’s April guidance directs administrators to relevant system-log detections, including “Suspected Credential Stuffing Attack (T1110.004).” Investigate failed logins, password-spray events, and targeted brute-force activity alongside that detection. A rise in failures is a reason to investigate, not proof that an account was compromised: establish whether any attempts succeeded and which accounts or configurations may need remediation.

Check Customer Identity Cloud cross-origin events

For Customer Identity Cloud tenants that use cross-origin authentication, Okta recommends reviewing these event types:

Rank #2
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • fcoa: failed cross-origin authentication.
  • scoa: successful cross-origin authentication.
  • pwd_leak: a password-leak event.

Okta’s Customer Identity Cloud post says suspicious activity began April 15, 2024, but does not say it was continuous for every tenant. Unexpected cross-origin events, a sudden rise in successful cross-origin events, or a rising failure-to-success ratio may indicate targeting. Investigate whether the activity is expected for your application and tenant; if credentials were compromised, Okta recommends rotating them immediately. See Okta’s Customer Identity Cloud guidance.

How to reduce credential-stuffing and account-takeover risk

Okta’s recommendations combine controls that limit automated attempts with authentication methods that make stolen passwords less useful. Their effectiveness, user friction, recovery implications, and availability vary by product and configuration; the cited sources do not provide a quantitative head-to-head test.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Control What it helps with Trade-off or implementation point
ThreatInsight in log-and-enforce mode Okta says ThreatInsight can block requests from IP addresses involved in large-scale credential attacks before authentication. Okta attributed cases where suspicious requests proceeded to authentication to a small percentage of customers with a combination of Classic Engine, ThreatInsight in Audit-only mode, and policies that permitted anonymizing proxies. Okta says customers using Identity Engine with ThreatInsight in log-and-enforce mode and denying access from anonymizing proxies were protected from the opportunistic attacks described in its post. This is Okta’s account of that observed activity, not a guarantee about every attack.
Restrictions on anonymizing proxies Can deny sign-ins routed through anonymizing services, one type of infrastructure Okta observed. Assess legitimate user and application needs before restricting access; the post does not quantify the resulting user impact.
CAPTCHA for risky sign-ins Adds a challenge to sign-ins judged risky, helping distinguish automated attempts. Introduces user friction. Okta recommends evaluating CAPTCHA challenges as part of layered defenses.
MFA Adds a factor beyond the password, reducing the value of a reused password by itself. Consider the sign-in experience and account-recovery path as well as enrollment and enforcement.
Passkeys and passwordless authentication Okta identifies passkeys as its preferred longer-term, phishing-resistant option; they do not depend on users entering a reusable password at sign-in. Plan for user enrollment, supported authenticators, and recovery. Okta recommends passkeys generally; its cited guidance does not require a particular hardware key.
Strong password policies and breached-password detection Can make weak or already exposed passwords harder to use successfully. These are among Okta’s Customer Identity Cloud recommendations; verify availability for your product edition and tenant.

Okta’s separate Customer Identity Cloud advice also says to restrict permitted origins when cross-origin authentication is necessary and disable the feature when it is not used. Review edition and plan eligibility before relying on any feature, since availability may depend on the product configuration. Okta’s May 2024 defense guidance discusses protections including password policies, breached-password detection, origin restrictions, and disabling unused cross-origin authentication.

A practical investigation sequence

  1. Check threat detections and sign-in patterns. Review the Okta system-log detection for suspected credential stuffing, then examine failed logins, password-spray events, and targeted brute-force activity.
  2. Look for successful access, not just blocked attempts. Identify accounts with successful sign-ins that coincide with suspicious activity and check whether the locations, devices, or application behavior are expected.
  3. For Customer Identity Cloud cross-origin flows, compare event types. Review fcoa, scoa, and pwd_leak events, and investigate unexpected events or changes in the failure-to-success pattern.
  4. Contain confirmed credential exposure. Rotate compromised credentials immediately, then assess affected accounts and configurations for remediation.
  5. Review preventive settings. Evaluate ThreatInsight enforcement, anonymizer restrictions, CAPTCHA for risky sign-ins, MFA or passkeys, and the origin and usage settings for cross-origin authentication.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the 2024 report does—and does not—show

Okta’s public posts establish an observed activity window and describe the infrastructure and defenses relevant to that activity. They do not publish a named threat actor, a total number of requests, an affected-account total, or evidence that the same spike continues in 2026. Treat the report as a dated warning and a useful guide to controls and log signals, not as a current incident alert.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.