Cyber actors attacking the Okta Help Center customer support management system in October downloaded a report containing the names and email addresses of all system users, and could use this information to target these customers via phishing and social engineering attacks, the company .

鈥淭he Okta breach exemplifies that even organizations with advanced cybersecurity defenses, including major cybersecurity firms, are not immune to successful cyberattacks by sophisticated adversaries,鈥� said John Riggi, AHA鈥檚 national advisor for cybersecurity and risk. 鈥淭his situation also generally highlights the significant and often unavoidable cyber risk exposure we face through the use of third-party software in our networks. Hospitals and health systems that use Okta services and technology should review the Okta advisory for possible cyber risk exposure, utilize phishing-resistant multifactor authentication, and alert help desk and general staff to possible advanced social engineering and phishing schemes based on the compromised Okta information.鈥�

For more information on this or other cyber and risk issues, contact Riggi at鈥�. For the latest cyber and risk resources and threat intelligence, visit鈥�aha.org/cybersecurity
 

Related News Articles

Headline
The FBI鈥檚 Internet Criminal Complaint Center May 15 released an alert warning of a malicious text and voice messaging campaign involving impersonators鈥�
Headline
In his latest AHA Cyber Intel blog, John Riggi, AHA national advisor for cybersecurity and risk, examines the state of cyber and physical threats in 2025 as鈥�
Headline
Health care had more cyberthreats last year than any other critical infrastructure industry, according to the FBI's 2024 Internet Crime Report released April鈥�
Headline
The National Security Agency April 23 released a report on operational technology systems that includes recommendations for security policies and technical鈥�
Chairperson's File
Public
Cybersecurity and physical threats are unfortunately significant enterprise risks for health care, regardless of size or location. Every hospital, physician鈥�
Headline
The Cybersecurity and Infrastructure Security Agency April 17 released guidance to reduce risks associated with a reported breach of Oracle cloud services.鈥�