Cyber actors attacking the Okta Help Center customer support management system in October downloaded a report containing the names and email addresses of all system users, and could use this information to target these customers via phishing and social engineering attacks, the company announced.

“The Okta breach exemplifies that even organizations with advanced cybersecurity defenses, including major cybersecurity firms, are not immune to successful cyberattacks by sophisticated adversaries,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “This situation also generally highlights the significant and often unavoidable cyber risk exposure we face through the use of third-party software in our networks. Hospitals and health systems that use Okta services and technology should review the Okta advisory for possible cyber risk exposure, utilize phishing-resistant multifactor authentication, and alert help desk and general staff to possible advanced social engineering and phishing schemes based on the compromised Okta information.”

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity
 

Related News Articles

Headline
New guidance released yesterday by the Cybersecurity and Infrastructure Security Agency, National Security Agency and FBI informs health care and other…
Headline
A joint advisory released Nov. 20 by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency and international partners warns of…
Headline
The Department of Justice Nov. 18 announced criminal charges against Evgenii Ptitsyn, a Russian national, for allegedly administering the sale, distribution…
Headline
A United Nations Security Council meeting the week of Nov. 4 discussed ransomware and the severe impacts that cyberattacks can have on hospitals and health…
Headline
AHA President and CEO Rick Pollack was recently a guest on Pinkston's "To the Point" podcast to discuss the future of U.S. health care, touching on a range of…
Headline
The Cybersecurity and Infrastructure Security Agency, FBI and other federal agencies have created a webpage with the latest cyberthreat updates and information…