The Room Where It Happens (Identity Compromise Edition): Behind the scenes of Okta attack campaigns
Julie Agnes Sparks (Security Research · Datadog)
BSidesSF 2026 · Day 1 · AMC IMAX
Overview
In "The Room Where It Happens (Identity Compromise Edition): Behind the scenes of Okta attack campaigns," Julie Agnes Sparks, a security researcher at Datadog, delivers a fast-paced and highly technical deep dive into the evolving landscape of identity compromise, specifically focusing on Okta environments. The talk addresses the critical challenge faced by security professionals navigating the extensive — yet often overwhelming — logging capabilities of Okta, an identity provider widely adopted across enterprises. Sparks' presentation aims to equip attendees with actionable strategies for threat hunting within their Okta logs, emphasizing practical approaches to detect emerging threats and respond effectively to sophisticated attack campaigns.

Key moments
- 0:00 Introduction to Okta attack campaigns and talk scope
- 2:00 Focusing on crucial Okta authentication and policy evaluation events
- 3:00 Essential Okta log fields for effective threat hunting
- 6:00 Evolution of attack campaigns: M365 to broader SaaS data exfiltration
- 7:00 Trends in attacker infrastructure: reused 'vibe coded' and free services
The Room Where It Happens (Identity Compromise Edition): Behind the scenes of Okta attack campaigns
Speakers: Julie Agnes Sparks
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=jEiwI5bJy2w
Overview
In "The Room Where It Happens (Identity Compromise Edition): Behind the scenes of Okta attack campaigns," Julie Agnes Sparks, a security researcher at Datadog, delivers a fast-paced and highly technical deep dive into the evolving landscape of identity compromise, specifically focusing on Okta environments. The talk addresses the critical challenge faced by security professionals navigating the extensive — yet often overwhelming — logging capabilities of Okta, an identity provider widely adopted across enterprises. Sparks' presentation aims to equip attendees with actionable strategies for threat hunting within their Okta logs, emphasizing practical approaches to detect emerging threats and respond effectively to sophisticated attack campaigns.
Sparks, with a background spanning detection engineering, threat hunting, and incident response, brings a wealth of experience in analyzing cloud infrastructure and SaaS application logs. Her insights are particularly relevant given the increasing reliance on identity providers like Okta as central points of access to critical business applications. The talk provides a crucial perspective on why organizations should prioritize understanding and leveraging their Okta logs, especially as adversaries shift their focus from direct application compromise to targeting the identity layer itself for broader lateral movement and data exfiltration.
This talk is important because it distills the complexities of Okta's vast logging ecosystem (comprising 1,081 event types) into a focused set of priorities for security teams. By highlighting specific log fields and event types, identifying shifts in attacker methodologies (from low-to-medium sophistication to advanced, "low and slow" campaigns), and offering concrete defensive strategies, Sparks empowers defenders to proactively secure their identity infrastructure. The emphasis on threat modeling, continuous hunting, and leveraging community resources provides a comprehensive roadmap for enhancing an organization's security posture against persistent and evolving identity-based threats.
Background
▶ Watch: Introduction to Okta attack campaigns and talk scope (0:00)
The proliferation of Software-as-a-Service (SaaS) applications and cloud infrastructure has cemented Identity Providers (IDPs) like Okta as critical control points for organizational access. While Okta offers extensive logging capabilities, with 1,081 documented event types, this sheer volume can be a double-edged sword for security teams. Sifting through such a massive dataset to identify genuine threats amidst legitimate user activity presents a significant challenge. Many organizations use Okta, but few fully leverage its forensic potential, often struggling to discern which logs truly matter for threat detection and incident response.
Historically, attackers targeted specific applications like Microsoft 365 (M365) or Google Workspace, with Okta compromise being a means to an end rather than the primary objective. These earlier campaigns, prevalent around 2025, were often characterized as low-to-medium sophistication, relying on common phishing or vishing tactics. Threat actors might use generic user agents or IPs associated with VPNs and proxy services, making detection somewhat straightforward through basic pattern matching and anomaly detection. Okta's own threat intelligence team and Datadog Security Labs have documented these traditional attack flows, where the goal was typically direct access to email or productivity suites for initial data exfiltration or reconnaissance.
However, the threat landscape has evolved significantly. Late 2025 into 2026 marked a critical shift, exemplified by campaigns attributed to groups like Shiny Hunters. These more sophisticated adversaries began viewing the IDP itself as a high-value target. Their primary goal expanded beyond direct access to a single SaaS application; instead, they sought to gain control over the Okta dashboard. This strategic pivot allows for broader lateral movement, enabling attackers to enumerate all applications a compromised user has access to, identify sensitive data repositories (such as Salesforce, Atlassian, Slack, DocuSign, Snowflake), and orchestrate comprehensive data exfiltration campaigns. This change in adversary focus necessitates a re-evaluation of defensive strategies, moving beyond simple authentication monitoring to a more holistic threat modeling approach centered on the IDP.
Key Findings
▶ Watch: Focusing on crucial Okta authentication and policy evaluation events (2:00)
The talk highlights several critical shifts and findings regarding modern Okta attack campaigns:
- Evolution of Adversary Goals: Earlier attacks (around 2025) typically targeted specific SaaS applications like M365 or Google Workspace, with Okta being a necessary but secondary target. The primary goal was often direct access to these productivity suites. However, more recent campaigns, such as those linked to Shiny Hunters, have shifted focus to gaining direct access to the Okta dashboard itself. This allows attackers to understand the full scope of a user's access, identify critical SaaS applications storing sensitive data (e.g., Salesforce, Atlassian, Slack, DocuSign), and plan broader data exfiltration or ransomware operations. This represents a move from opportunistic access to strategic lateral movement within an organization's entire SaaS ecosystem.
- Increased Sophistication and Persistence: While low-to-medium sophistication attacks using brute force or social engineering against legacy protocols persist, there's a notable rise in "low and slow" attempts. These attacks are significantly harder to detect as they often involve infrequent login attempts, varied IP addresses, and different user accounts over extended periods, making traditional anomaly detection challenging. Attackers are also employing more believable phishing infrastructure, often using "vibe coded" (reused and slightly modified) kits and leveraging free hosting services like Render to create convincing fake login pages and interactive dashboards to manage their campaigns.
- Criticality of Okta Log Visibility: Despite the vast number of Okta event types, the talk emphasizes that focusing on authentication events and policy evaluation events is paramount. These two categories provide insights into user login attempts, the factors used (e.g., password, MFA), the policies applied (e.g., requiring 2FA, managed device), and the target applications. Key log fields like session IDs, dthash (device hash), and debug context debug data.behaviors (which includes risk, anomaly, new device/geolocation indicators) are indispensable for effective threat hunting.
- Policy Misconfigurations as Major Gaps: A significant finding is that many compromises occur due to subtle misconfigurations in Okta sign-on policies. Okta's policy evaluation system, which prioritizes policies based on a 1-99 numbering scheme, can inadvertently allow a less secure policy (e.g., single-factor authentication) to override a more secure one (e.g., phishing-resistant MFA) for a subset of users. This "slippery slope" means that even if 90% of employees are under appropriate policies, a small percentage with misconfigured access can create a critical vulnerability.
- Proactive and Continuous Threat Hunting: The dynamic nature of these attacks necessitates a shift from reactive incident response to proactive and continuous threat hunting. This includes not only threat modeling the Okta instance itself but also extending hunts to other integrated SaaS applications. Leveraging community resources like Okta's public customer detections repository, the MITRE ATT&CK identity provider matrix, and the speaker's own "SaaS forensic ideas" repository are highlighted as essential starting points for developing tailored, continuously executing hunting queries.
Technical Deep Dive
▶ Watch: Essential Okta log fields for effective threat hunting (3:00)
Effective threat hunting in Okta environments hinges on understanding specific log types and fields, as well as the underlying mechanisms of authentication and policy enforcement. Julie Sparks distilled Okta's 1,081 event types into a manageable focus, emphasizing authentication events and policy evaluation events.
Key Log Fields for Threat Hunting:
Sparks highlighted several crucial fields present across various Okta logs that provide deep visibility into user activity and potential compromise:
- session IDs: These unique identifiers link a series of related authentication and application access events, allowing security analysts to trace a user's entire session journey. This is fundamental for understanding the scope of a compromised session.
- dthash (Device Hash): More sophisticated than a simple user agent string, the
dthashis a composite hash generated from multiple device characteristics. It's invaluable for identifying when a single device attempts to log into multiple user accounts, which is a strong indicator of compromise or enumeration attempts. - debug context debug data.behaviors: This field is a treasure trove of security intelligence. It encompasses various sub-fields related to risk scores, behavioral anomalies, and contextual information such as whether the login originated from a new device, a new geolocation, or exhibited other suspicious characteristics. While potentially noisy, when tuned with a narrower hunt scope, it can pinpoint unusual activity.
- factor: This field explicitly states which authentication factor was used for a login attempt (e.g., password, Okta Verify push, SMS, WebAuthn/FIDO2). Monitoring this helps identify if attackers bypass strong MFA or if weaker factors are being utilized where stronger ones are expected.
- target app / target.display name: These fields indicate the specific application or resource the user was attempting to access. This is crucial for understanding an attacker's objective post-authentication and tracking lateral movement attempts.
The Compromise Flow:
Sparks outlined a common, albeit sometimes benign, compromise flow that defenders must be able to distinguish from legitimate activity:
- Policy Evaluation: A user attempts to sign in. Okta evaluates the attempt against configured policies.
- Challenge/MFA: If policies require it, a challenge (e.g., a push notification to Okta Verify) is issued.
- Behavioral Flags: Okta's security behaviors (from
debug context debug data.behaviors) might flag the attempt as a new geolocation or new device. - Successful MFA (Compromised): The MFA challenge is successfully provided, potentially by the legitimate user falling for a phishing attack or the attacker intercepting the MFA response.
- Application Access: The attacker successfully gains access to a target application, such as Google Workspace.
The challenge lies in the fact that many of these individual steps can be legitimate (e.g., a user getting a new phone, logging in from a new location while traveling). The "low and slow" nature of modern attacks further complicates detection, as an anomaly detection rule set for a short period might miss an attacker who logs in at 8 AM and then again at 2 AM the next day from a different VPN.
Defensive Mechanisms and Configuration:
- Auditing Sign-in Policies: Okta's policy engine uses a priority system (1-99), where the highest-numbered policy takes precedence. A critical technical gap identified is the accidental presence of lower-priority, less secure policies (e.g., single-factor authentication) that can override stronger, phishing-resistant MFA policies for specific user groups. Regular, meticulous auditing of all sign-on policies across different groups and departments is essential to prevent these "slippery slope" vulnerabilities.
- Phishing-Resistant MFA: Implementing and enforcing phishing-resistant MFA (e.g., FIDO2/WebAuthn) is a cornerstone defense. This technology cryptographically binds authentication to the originating website, making it resilient against adversary-in-the-middle (AiTM) phishing attacks.
- Device Management Integration: Integrating an MDM (Mobile Device Management) solution with Okta allows for device context in policy evaluations. Policies can then require that access only be granted from managed, compliant devices, significantly reducing the attack surface.
Leveraging Community Resources:
- MITRE ATT&CK Identity Provider Matrix: This framework provides a structured approach to understanding adversary tactics and techniques against identity providers, serving as an excellent starting point for threat hunts.
- Okta's Public Customer Detections Repository: Okta maintains a public GitHub repository with recommended detections and hunting queries, often in Okta Query Language (OQL), which can be adapted for various SIEM platforms.
- SaaS Forensic Ideas Repository: The speaker's own repository offers guides and insights into logging nuances across various SaaS applications, helping analysts understand what to look for beyond standard documentation.
By focusing on these technical details, security teams can move beyond generic log monitoring to implement targeted, effective threat detection and response strategies within their Okta environment.
Demo / Proof of Concept
▶ Watch: Evolution of attack campaigns: M365 to broader SaaS data exfiltration (6:00)
While the talk did not feature a live, interactive demonstration of an attack or a defensive tool, Julie Sparks effectively illustrated the attacker's methodology and the visual realism of modern phishing campaigns through several screenshots and diagrams. These served as critical proof points for the concepts discussed.
One key visual was a diagram illustrating the adversary-in-the-middle campaign flow (4:30), which depicted how attackers would target M365 or Google Workspace by intercepting authentication flows. This diagram, from a Datadog Security Labs post, showed the traditional phishing approach.
A more contemporary illustration highlighted the shift in attacker infrastructure. Sparks presented a screenshot of a fake "turnstile" page (8:00) that attackers use. This page, designed to look like a legitimate connection verification step, acts as a gate to determine if the victim should be pushed through the full phishing workflow, including asking for an OTP (One-Time Password) or capturing credentials. This demonstrates the attackers' need for interactive dashboards and control panels, which they often host on free services like Render. The use of Render, known for its generous free tier, lowers the barrier to entry for attackers to build out these sophisticated, multi-stage phishing operations.
Further emphasizing the realism, Sparks showed screenshots of very believable fake Okta login pages (8:00). These pages are meticulously crafted to mimic the legitimate Okta interface, making it extremely difficult for an average user to distinguish between the authentic portal and the phishing site. These visual examples underscore the sophistication of modern phishing kits and the challenge users face in identifying malicious prompts.
The talk also included a high-level diagram from Google's threat intelligence group (6:00) illustrating the Shiny Hunters' campaign goals. This diagram visually conveyed how attackers aim to gain initial access, pivot to various SaaS apps (not just M365/Google Workspace), and ultimately achieve data exfiltration for ransom or other malicious purposes.
These visual aids, though static, served as powerful "proof of concept" examples, demonstrating the practical application of the attacker techniques and infrastructure discussed, and reinforcing the urgency of the defensive strategies presented.
Defensive Implications
▶ Watch: Trends in attacker infrastructure: reused 'vibe coded' and free services (7:00)
Understanding the evolving threat landscape in Okta environments provides critical insights for strengthening an organization's defensive posture. Julie Sparks outlined several key strategies for defenders:
- Comprehensive Threat Modeling of Okta:
- Identify Lateral Movement Paths: Security teams must meticulously threat model their Okta instance. This involves asking: What lateral movement is possible from a compromised Okta dashboard? If an attacker gains access to the Okta administration interface, what critical SaaS applications (e.g., Salesforce, Snowflake, DocuSign, Atlassian) can they pivot to?
- Data Location Awareness: Pinpoint where sensitive customer data, intellectual property, or critical business information is stored across all integrated SaaS apps. This prioritization helps direct hunting efforts and incident response plans to the highest-risk areas.
- Cross-Platform Hunting: Recognize that an Okta compromise is rarely isolated. Defenders need to develop follow-up hunts and detections that combine Okta data with logs from other SaaS applications (e.g., Slack, Salesforce, CloudTrail for AWS environments) to trace full attack chains.
- Proactive Policy Auditing and Enforcement:
- Regular Policy Review: The most significant gap identified is often misconfigured sign-on policies. Organizations must regularly audit their Okta sign-on policies, paying close attention to the priority order (1-99). Ensure that no legacy or inadvertently created policies allow for weaker authentication (e.g., single-factor password-only access) for any user group, especially engineers or privileged accounts.
- Phishing-Resistant MFA: Mandate and enforce phishing-resistant Multi-Factor Authentication (MFA), such as FIDO2/WebAuthn, across the entire organization. This is the most effective technical control against AiTM phishing campaigns.
- Device Management Integration: Integrate MDM (Mobile Device Management) with Okta to enable policies that require access only from managed and compliant devices. This adds another layer of defense by ensuring device health and ownership.
- Continuous Threat Hunting and Detection Engineering:
- Leverage Community Resources: Start with established resources. Utilize the MITRE ATT&CK Identity Provider Matrix for structured hunting. Explore Okta's public customer detections repository for recommended hunts and detections, adapting them to your SIEM. The speaker's SaaS forensic ideas repository also offers valuable insights into logging nuances across various SaaS platforms.
- Tailored, Continuous Queries: Develop tailored hunting queries specific to your environment and execute them continuously, ideally displayed in a security dashboard. This allows for ongoing monitoring of suspicious indicators (e.g., specific user agents, IP addresses, behavioral chains) and quickly identifies emerging threats or re-emerging indicators from past incidents. This approach bridges the gap between ad-hoc hunts and static detections.
- FastPass Failure Analysis: Implement monitoring for Okta FastPass failure events. While not 100% reliable, roughly half the time these failures can reveal active phishing infrastructure by showing the originating URL or other suspicious browser interactions. This provides an early warning signal for ongoing attacks.
- Proactive External Threat Intelligence and Monitoring:
- URLScan and VirusTotal: Actively use tools like URLScan and VirusTotal to monitor for phishing infrastructure targeting your brand. Search by brand name, keywords, or use similarity algorithms based on known past phishing sites.
- Automated Alerts: Set up automated alerts (e.g., email, Slack notifications) for new phishing infrastructure detections. Staying ahead of attackers by identifying their infrastructure before users interact with it is a critical proactive measure.
- Threat Intel Integration: Integrate active threat intelligence feeds to stay informed about new tactics, techniques, and procedures (TTPs) used in identity compromise campaigns.
By adopting these comprehensive defensive strategies, organizations can significantly reduce their attack surface, improve their detection capabilities, and enhance their resilience against sophisticated identity-based attacks targeting Okta and its integrated SaaS ecosystem.
Key Takeaways
- Focus on Critical Okta Logs: Despite 1,081 event types, prioritize authentication events and policy evaluation events. Key fields like
session IDs,dthash,debug context debug data.behaviors,factor, andtarget appare essential for effective threat hunting. - Evolving Adversary Tactics: Modern attackers, exemplified by groups like Shiny Hunters, increasingly target the Okta dashboard itself for lateral movement and broad data exfiltration across all integrated SaaS applications (e.g., Salesforce, Atlassian, Slack), rather than just direct access to specific apps like M365.
- Policy Auditing is Paramount: Regularly audit Okta sign-on policies, paying close attention to the 1-99 priority system. Even a small number of users under a misconfigured, less secure policy can create a critical vulnerability, undermining stronger security controls like phishing-resistant MFA.
- Implement Phishing-Resistant MFA and Device Management: Enforce phishing-resistant MFA (e.g., FIDO2/WebAuthn) and integrate MDM (Mobile Device Management) with Okta to require access from managed devices. These are crucial technical controls against sophisticated phishing and identity compromise.
- Embrace Continuous Threat Hunting: Move beyond reactive incident response to proactive, continuous threat hunting. Leverage resources like the MITRE ATT&CK Identity Provider Matrix, Okta's customer detections repository, and the SaaS forensic ideas repository to build tailored, continuously executing queries that monitor indicators across Okta and other SaaS apps.
- Proactive External Monitoring: Utilize tools like URLScan and VirusTotal to proactively monitor for phishing infrastructure targeting your brand. Identifying attacker infrastructure before it impacts your users is a critical early warning capability.
About the Speaker(s)
Julie Agnes Sparks is a security researcher at Datadog, where she focuses on identifying emerging threats by analyzing cloud infrastructure and SaaS application logs. Her expertise spans detection engineering, threat hunting, and incident response. With a deep understanding of the intricacies of identity providers like Okta, she frequently delves into the nuances of logging visibility and behavioral analysis to uncover sophisticated attack campaigns. Julie is known for her fast-paced, highly informative presentations, aiming to provide actionable intelligence to security professionals.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent, practitioner-focused talk from someone who clearly works in this space daily. Sparks knows her Okta logs cold, and the policy misconfiguration angle plus the FastPass failure-as-phishing-signal tip are genuinely useful. But nothing here crosses into original research territory — this is distillation and operational guidance, not novel discovery.
Heather Calloway (CISO) — SOLID
Sparks delivers a technically credible, defender-focused breakdown of Okta threat hunting that will be genuinely useful for detection engineers and SOC analysts. The policy misconfiguration finding is the sharpest moment in the talk, but the presentation stays at the practitioner layer and never climbs to the governance or accountability questions that make identity compromise a board-level problem.