Talk to an Expert
Blog · March 25, 2022

Your identity management platform may be at risk, whether your organization is big or small

It was an eye opener to find out the security of the world’s most critical companies is more fragile than we thought due to the breach of a widely used identity management platform.

Just recently there was a potential breach of extensive source code of a big and secure organization like Microsoft -Bing search engine (Bing Maps and Cortana virtual assistant software) and Twitter meltdown in 2020’s where attackers included 17-year-old Minecraft scammer taking over an administrative account. However, this case is even more alarming and really, really bad…according to WIRED “Lapsus$ Extortion Group Claims Okta Hack, Microsoft Source Code Leak“.

On Monday, March 21st, a recently emerged hacking group by the name of Lapsus$ Gang claimed that it took control of an Okta administrative or “super user” account on January 21. It shared an online screenshot to back up its claim.

Established in 2009, Okta is an independent provider of an identity management platform. The Okta Identity Cloud is intended all organizations to both secure and manage their extended enterprise and used by thousands of large organizations to log in without juggling a dozen passwords.

The company’s stock price fell by 6 percent on Tuesday morning following the news. Lapsus$ has been stealing source code and valuable data from prominent companies like Nvidia, Samsung and Ubisoft.

Now for your reality check.

Is your organization’s identity management platform secure enough?

What can we learn from this incident?

How can RegDOX help with above areas and beyond?

End-to-End Protection

Collaboration with External parties

Compliant with government regulations

If the features above had been implemented, Okta’s administrative access would not have been compromised. In addition, Okta’s reputation would not have been hurt so badly with lost trust in the company, which is supposed to be ‘secure’ platform.

Contact Us

See the enclave in action.

The Compliant Computing Enclave keeps CUI inside one boundary, with your endpoints out of scope and the evidence trail already built.

Talk to an Expert
Keep reading

More from the blog

September 3, 2026

Week 6: Too Embedded to Reject

How GCC High vendor lock-in changes the decision Last week, we examined the assessor problem. This...

Read it →

August 26, 2026

Week 5: FedRAMP’s Assessor Problem

Why FedRAMP assessor independence matters Last week, we examined the larger architecture problem. This week, we...

Read it →

August 20, 2026

Week 4: The Problem Did Not Stop with Encryption

Why GCC High security architecture matters Last week, we focused on the encryption question. This week,...

Read it →