Summary
- Environment: Communications/API
- Operational impact: Customer data accessed
- Financial impact: No financial figure is established by the reviewed source evidence
- Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.
What happened
Impact
- Documented impact: Customer data accessed. [1]
- No financial loss, ransom amount, recovery cost, or regulatory penalty is established by the reviewed source evidence.
Timeline
Documented public update
The August 2022 social engineering attack records the incident facts used in this briefing.
[1]Briefing updated
This briefing was last reviewed and updated on September 19, 2026.
Threat Group & Attack Vector
The retained source describes the attack path as follows: 0ktapus phishing kit; SMS phishing of employees for Okta credentials. The canonical record does not add intrusion steps beyond those supported by the source. [1]
Actors
- 0ktapus — identified in the supported attack description. [1]
TTPs
- T1566 — Phishing — mapped from the cited behavior. [1]
Response
The retained source describes containment action intended to limit further access or disruption. [1]
This account is bounded to August 2022 social engineering attack. Details absent from that evidence are left unresolved rather than inferred. [1]
