Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português

Info icon Announcement: 2026 KuppingerCole PAM Leadership Compass: BeyondTrust recognized as an Overall Leader and top Product Leader among 36 evaluated vendors. Access the Report

  • Home
  • Resources
  • Webinars
  • From the Trenches: How BeyondTrust Detected a Breach at Okta and Lessons We Keep Learning from This Story current page
Link copied

From the Trenches: How BeyondTrust Detected a Breach at Okta and Lessons We Keep Learning from This Story

with Randy Franklin Smith, CEO, Monterey Technology Group, Inc. CISA, SSCP, Security MVP; Fletcher Davis, Director of Research at BeyondTrust
Webinars default
From the Trenches: How BeyondTrust Detected a Breach at Okta and Lessons We Keep Learning from This Story

Get Instant Access to this Content

Learn more about how to secure your business from threats in places you didn't even know existed.

About the Session

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

This is the story of how an attacker gains access to an identity provider’s support case portal, harvests a key piece of data from a file uploaded to the case by a customer and within minutes uses that data to gain access to the systems at that customer.

But it’s also a story of victory and a real-world demonstration of the power of monitoring, policy and defense-in-depth.

The Okta/BeyondTrust/Cloudflare incident happened a while back, but it remains the most valuable breach account we have to understand today’s threats in this multi-cloud, distributed and hybrid environment in which we currently fight the good fight. And last week I met Fletcher Davis at BeyondTrust. Fletcher is the Senior Manager of the Research Team at BeyondTrust and has an inside view of this breach. Before BeyondTrust, he was a red teamer at CrowdStrike and Mandiant, so I’m excited that he agreed to join me for this real training for free / anatomy of an attack session.

We will postmortem this breach step-by-step and it includes a bit of everything:

  • The crucial role of MFA and the difference between weak and strong MFA
  • Endpoint security
  • Web API security
  • Tokens, session cookies
  • HAR files
  • Security dependencies between systems and partners
  • Alerting on changes in privileged accounts and entitlements
  • Detecting unusual patterns in web authentication
  • The importance of communication between business partners and the sometimes frustrating process of escalation and getting people to take you seriously
  • Implementing non-default policies specific to your organization
  • Service account management

This fascinating story provides a wealth of lessons we can apply. We will finish up with a list of actionable recommendations that every organization can put to work in any environment.

BeyondTrust was able to detect and immediately respond thanks to their practice of dogfooding their products to protect their own network and Fletcher Davis will briefly show you a demo of the Insights platform and walk through some of the detections that caught the breach, as well as some recent additions that give customers visibility into their Okta privileges and application assignments.

Meet the Speakers

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Randy Franklin Smith
Randy Franklin Smith
CEO, Monterey Technology Group, Inc. CISA, SSCP, Security MVP
Randy Franklin Smith
CEO, Monterey Technology Group, Inc. CISA, SSCP, Security MVP

Randy Franklin Smith is an internationally recognized expert on the security and control of Windows and Active Directory security who specializes in Windows and Active Directory security. He performs security reviews for clients ranging from small, privately held firms to Fortune 500 companies, national, and international organizations.

×
Fletcher Davis
Fletcher Davis
Director of Research at BeyondTrust

Recommended Resources

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Research
2025 Microsoft Vulnerabilities Report
Resources
Paths to Privilege Explained
Videos
Identity Security Insights® Assessment
Blog
Microsoft Security in 2025: Top Vulnerability Trends from the BeyondTrust Microsoft Vulnerabilities Report
Blog
A Guide to Using Longitudinal Data Analysis for Improved Identity Threat Detection
Blog
BeyondTrust Identity Security Insights: 2024 Wins and the Roadmap to Advanced Identity Security Posture Management
Podcasts
Ep. 77 - Bugs in the System: When Moths Hack Power Plants // Lesley Carhart
Podcasts
Ep. 76 - Phishing, Predictions, and Starship Troopers // Brian Kime
Podcasts
Ep. 75 - DOS Viruses & Catching Chinese APT Hackers // Roger Grimes
Latest
  • The Ghost in the Machine (Securing Non-Human Identities)
    Jun 18, 2026 The Ghost in the Machine (Securing Non-Human Identities)
    Webinar
Related
  • APJ Tech Talk Tuesday The Essential Eight Compliance with BeyondTrusts Endpoint Privilege Management
    Jul 10, 2023 APJ Tech Talk Tuesday The Essential Eight Compliance with BeyondTrusts Endpoint Privilege Management
    On-demand we...
    32m
Share this Article
  • Link

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.