{
  "type": "bundle",
  "id": "bundle--f0eebf7b-acca-52ea-8709-825ea8629de3",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--513f75e7-397f-587d-8608-18d665bfe323",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:01b86e2b-f9e1-570a-a581-9952a5dde6ef",
      "name": "Okta",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--879cd14a-1100-5d15-8776-e8bb3c1cc590",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:5accb983-1070-5be5-97ce-578807d5e182",
      "name": "Okta support-system breach security incident"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--ecbf38a0-a622-5446-8d00-286d9e8397c0",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:d0f5c838-8ee2-53ee-9b30-0a0d8286ec49",
      "name": "Okta support-system breach security incident"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--89c31f08-d3c4-5b5a-8e37-acbd4b514c28",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:03062f56-b205-56ad-b39e-76bc8ad1578e",
      "relationship_type": "affected-organization",
      "source_ref": "incident--879cd14a-1100-5d15-8776-e8bb3c1cc590",
      "target_ref": "identity--513f75e7-397f-587d-8608-18d665bfe323",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Okta",
          "url": "https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/",
          "external_id": "cit:db7b0ed7-a7ef-55b7-848d-5fa0f457474c",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9b526e3864d00dcc39dccb79ef240d8cd39d1a1710b9287580a1733ef9fd2332"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--1862961c-9389-50c4-89ce-fdeddaaa28de",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:72b21fa2-5617-584b-b0b2-df6de72dcfb5",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Okta",
          "url": "https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/",
          "external_id": "cit:495b2cd4-8341-5a59-9639-26389c5b7482",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9b526e3864d00dcc39dccb79ef240d8cd39d1a1710b9287580a1733ef9fd2332"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "date",
        "value": "2023-11-03"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--39dd9d2b-7034-5cd9-8efc-5240d173f93c",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:b2f01b01-a1bb-53a0-8000-3d98fc2fea4b",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "Okta",
          "url": "https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/",
          "external_id": "cit:3d4eee76-afa7-55cc-a395-ae5b069ccfc6",
          "description": "Unauthorized Access to Okta's Support Case Management System: Root Cause and Remediation",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9b526e3864d00dcc39dccb79ef240d8cd39d1a1710b9287580a1733ef9fd2332"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Compromised credential in Okta's own support case management system."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--6e9735c9-0ed8-5d3d-894d-879a12c38c6d",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:6af487b7-2690-5e5c-a318-36fa682b1665",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Okta",
          "url": "https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/",
          "external_id": "cit:76621d7f-f827-563c-b130-ba8f6bb53b64",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9b526e3864d00dcc39dccb79ef240d8cd39d1a1710b9287580a1733ef9fd2332"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the okta support-system breach security incident involving Okta."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--f369d7a0-0c8d-53f0-8efd-0900d0ca62ee",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:8fb67854-c73a-5e54-a67e-1469815c7ffe",
      "confidence": 84,
      "external_references": [
        {
          "source_name": "Okta",
          "url": "https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/",
          "external_id": "cit:7cf68eba-01f3-55c8-97d0-2042e354335e",
          "description": "2023-10-17 Okta Security copies and examines all files identified in the customer support system logs that were accessed by the threat actor. 134 Okta customers or less than 1% of Okta customers had a file accessed by the threat actor.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9b526e3864d00dcc39dccb79ef240d8cd39d1a1710b9287580a1733ef9fd2332"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Session tokens/cookies customers had uploaded in support tickets were stolen and used to pivot into customer environments (incl. BeyondTrust, Cloudflare, 1Password)."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--ff10ce7d-1998-5a33-835f-94051028286c",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:12ce71e3-6658-52b8-b30e-71ae6c9b3e62",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "Okta",
          "url": "https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/",
          "external_id": "cit:8e523143-756d-50ad-9cb7-d7b455f7e0f3",
          "description": "Some of these files were HAR files that contained session tokens which could in turn be used for session hijacking attacks.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9b526e3864d00dcc39dccb79ef240d8cd39d1a1710b9287580a1733ef9fd2332"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes containment action intended to limit further access or disruption."
      }
    },
    {
      "type": "x-ally-event",
      "spec_version": "2.1",
      "id": "x-ally-event--d2ceac5d-50ff-564d-8024-a907fe766e87",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "evt:bfef40bc-1437-5d04-a259-21cea0a9d450",
      "name": "Documented public update"
    }
  ]
}
