In October 2023, Okta disclosed its support system was breached, and customer-uploaded HTTP Archive (HAR) files were accessed, including session tokens and user cookies. Okta revoked the session tokens and advised customers to sanitize these files. Both BeyondTrust and Cloudflare detected malicious activity related to this breach and were able to respond quickly. Only to realize later some access tokens had not been properly rotated.

