Okta is an identity and access management company, facilitating single sign-on between itself and service providers.
Additionally, Okta provides API access management, MFA, and other identity and management solution, making it a prime target for attackers.
Initial Access
Stolen Credentials leading to valid account access
confirmed
Attackers used stolen credentials likely found from dumps online to successfully login to an employee's personal Google account, which also had saved credentials for a service account that had permissions to view and update support cases.