Help-Desk Compromise Enables Persistent Access Across Okta Tenants

Attackers are no longer just stealing credentials; they are exploiting trusted business process outsourcers (BPOs) and help-desk workflows to gain persistent access inside multiple Okta tenant environments. The UNC6783 extortion campaign uses live-chat social engineering to direct support staff to malicious Okta login pages, bypassing multifactor authentication with phishing kits. They then enroll their own devices, turning a one-time login compromise into a long-term foothold. This shifts the unit of compromise from individual user accounts to the identity control path itself, expanding the blast radius across vendor relationships. This campaign targets dozens of organizations by abusing trust in outsourced support and identity recovery processes. The use of attacker-enrolled devices means attackers maintain persistent access even after credential resets. This is not a patch-now vulnerability but a critical update to threat models for organizations relying on Okta and third-party BPO

Part of the PlainSec briefing for 2026-04-08

Sources