HackingSupply Chain (3P Vendor)Employee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
OKTA, INC.
bd_fa30b6db14c160bb · schema v1 · pii pii-v1
Full breach record for OKTA, INC. →Okta, Inc. notified the California Attorney General of a data breach involving its third-party vendor, Rightway Healthcare, Inc. An unauthorized actor gained access to an eligibility census file on September 23, 2023. Okta discovered the incident on October 12, 2023. Affected data included names, Social Security Numbers, and health insurance plan numbers for current and former employees and their dependents. Okta is offering 24 months of credit monitoring and identity restoration services through Experian.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_97d1456d54eb792bMaine State AGfiled 2023-11-01Candidate
- bd_9db6f19d07f176a7Montana State AGfiled 2023-11-01Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-575996
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 1, 2023
- Raw hash
- 09acba6afc844e2681a6ff95fdeafcf77af8e7b39e695c35b9a232705266649a
Reporting entity
- Name
- OKTA, INC.norm: okta
Victim entity
- Name
- OKTA, INC.norm: okta
Incident
- Discovered
- Oct 12, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Rightway Healthcare, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.