Okta is an identity and access management company, facilitating single sign-on between itself and service providers.
Additionally, Okta provides API access management, MFA, and other identity and management solution, making it a prime target for attackers.
Initial Access — Stolen Credentials leading to valid account access
Confidence: confirmed
Attackers used stolen credentials likely found from dumps online to successfully login to an employee's personal Google account, which also had saved credentials for a service account that had permissions to view and update support cases.