
Okta has concluded its investigation into its recent data breach incident, concluding that it was - most likely - due to an employee storing their login credentials into their private Google profile in the Chrome browser and then logging in on a company endpoint.
In an announcement published on the Okta website, the company’s Chief Security Officer David Bradbury said the threat actor abused a service account that was stored in Okta’s system.