Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The headline refers to a social-engineering campaign reported by multiple US-based Okta customers in 2023—not a newly disclosed 2026 incident. Attackers targeted IT service desks to reset multifactor authentication (MFA) factors for highly privileged accounts, then used administrator access to change identity settings and, in some cases, impersonate users through inbound federation.

What attacks does the title refer to, and when did Okta disclose them?

Okta published its analysis, “Cross-Tenant Impersonation: Prevention and Detection,” on August 31, 2023. SecurityWeek published the matching headline on September 5, 2023. Okta’s article changelog records updates on September 9, 2023, and March 8, 2024. The account concerns reports from multiple US-based customers; Okta did not publish a campaign-wide customer count. At the time of SecurityWeek’s report, the threat actor’s identity and ultimate goal had not been disclosed. Okta’s analysis and SecurityWeek’s September 2023 report describe the event.

This campaign should not be conflated with Okta’s separate October 2023 customer-support-system incident. The 2023 report discussed here describes social engineering of customers’ IT service desks.

How did attackers compromise privileged accounts?

Attackers contacted targeted organizations’ IT service desks and tried to persuade staff to reset all MFA factors for highly privileged accounts, particularly Super Administrators. Before calling, they appeared either to have privileged-account passwords already or to be able to manipulate delegated authentication through Active Directory.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After obtaining access, attackers could use administrator capabilities to make further identity changes. Okta observed actions including assigning higher privileges to other accounts, resetting authenticators for existing administrators, and removing second-factor requirements from authentication policies. The sequence shows why account recovery and help-desk verification are part of the identity security boundary: a strong sign-in factor does not stop an unauthorized reset if staff can be deceived into removing it.

How did inbound federation enable impersonation?

Inbound federation lets a person authenticated by a source identity provider (IdP) access applications at a target provider. It can support legitimate needs such as just-in-time provisioning, mergers, and globally managed applications. Okta reported that attackers configured a second IdP they controlled as an “impersonation app,” then manipulated a username parameter at the source IdP to match a real user in the target organization. That could enable single sign-on as the matched user.

The risk is not that federation is inherently malicious; it is that changes to federation settings can have broad identity consequences. Okta’s account makes the practical control point clear: tightly restrict who can create or modify identity providers and monitor those changes.

What should Okta administrators do to protect Super Administrator accounts?

Okta’s recommendations span authentication, recovery, privilege management, and monitoring. Applying only one layer leaves the others exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Strengthen authentication and sensitive actions

  • Require phishing-resistant authentication, such as FastPass or FIDO2 WebAuthn. A compatible FIDO2 security key is one possible way to use WebAuthn, but it does not prevent a social-engineered factor reset by itself.
  • Require re-authentication for sensitive administrator actions, and set policies so administrators re-authenticate at every sign-in to privileged applications.
  • Use dedicated policies for administrators that require phishing-resistant authentication and managed devices.
  • Bind administrative app sessions to the session context, reducing the value of a stolen or replayed session.

Harden help-desk verification and recovery

  • Use strong identity checks before changing an account’s authenticators; Okta specifically recommends visual verification.
  • Start recovery with the strongest authenticator available and restrict recovery flows to trusted networks.
  • Restrict the remote-management tools available to help-desk staff, limiting the risk that those tools become a route into privileged systems.

Reduce standing privilege

  • Use least-privilege custom administrator roles rather than granting broad administrator rights by default.
  • Adopt zero standing privileges where practical, so elevated access is not continuously available.
  • Require dual authorization for just-in-time privilege elevation.
  • Restrict the ability to create or modify identity providers, given the potential for federation configuration to enable cross-tenant impersonation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What activity should security teams monitor?

Okta’s analysis identifies several detection opportunities. Teams should map these to their current Okta logging, alerting, and interface labels, since the event names and query examples in the 2023 article are historical product details.

  • MFA factor resets, especially for administrators or other highly privileged users.
  • Suspicious activity reports and administrator-console access that is unusual for the account, device, network, or time.
  • Creation or modification of identity providers and sign-ins through third-party identity providers.
  • Proxy-based sign-ins and new-device activity; Okta also recommends notifications for new devices and suspicious activity.

Correlating these signals can help distinguish an isolated support interaction from a chain involving factor resets, new privileges, federation changes, or unusual administrator access. Okta summarized the importance of privileged-account protection this way: “These recent attacks highlight why protecting access to highly privileged accounts is so essential.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.