Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
The 0ktapus threat group conducted a large-scale phishing campaign targeting over 130 companies, primarily aiming to steal Okta identity credentials and multi-factor authentication (MFA) codes. The attackers sent text messages with links to phishing sites mimicking the Okta authentication pages of targeted organizations. This campaign compromised nearly 10,000 accounts across more than 130 organizations, including 114 US-based firms and victims in 68 other countries. Initial attacks targeted telecommunications companies to gather phone numbers used in MFA attacks. The ultimate goal was to access internal systems and facilitate supply-chain attacks. The campaign demonstrated how attackers can bypass MFA protections through phishing. Researchers recommend using FIDO2-compliant security keys and educating users about MFA attack methods to mitigate such threats.
AI Analysis
Technical Summary
The 0ktapus threat group executed a sprawling phishing campaign that spoofed Okta's multi-factor authentication system to steal identity credentials and MFA codes from employees of over 130 organizations. The campaign began by targeting telecommunications companies to collect phone numbers, then sent phishing SMS messages containing links to fake Okta login pages. Victims submitted their credentials and MFA codes, enabling attackers to compromise 9,931 accounts. The attackers aimed to access company mailing lists and customer-facing systems to facilitate supply-chain attacks. The campaign affected primarily US-based firms but also victims in 68 other countries. The campaign highlights the ability of phishing attacks to circumvent MFA protections, emphasizing the need for stronger authentication methods such as FIDO2 security keys and user education on MFA attack vectors.
Potential Impact
The campaign compromised nearly 10,000 accounts across over 130 organizations, including 114 US-based companies and victims in 68 additional countries. Attackers obtained Okta credentials and MFA codes, enabling unauthorized access to internal tools and systems. In a related incident, DoorDash reported unauthorized access to internal tools and theft of personal information of customers and delivery personnel. The campaign demonstrates that MFA, while a strong security control, can be bypassed through sophisticated phishing attacks, leading to significant data breaches and potential supply-chain compromises.
Mitigation Recommendations
No official patch or fix applies as this is a phishing campaign rather than a software vulnerability. Researchers recommend using FIDO2-compliant security keys for MFA to provide phishing-resistant authentication. Additionally, organizations should educate users about common MFA attack techniques and how to recognize and respond to phishing attempts. Good hygiene around URLs and passwords is also advised. There is no indication that the threat has been fully mitigated or that no action is required.
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Description
The 0ktapus threat group conducted a large-scale phishing campaign targeting over 130 companies, primarily aiming to steal Okta identity credentials and multi-factor authentication (MFA) codes. The attackers sent text messages with links to phishing sites mimicking the Okta authentication pages of targeted organizations. This campaign compromised nearly 10,000 accounts across more than 130 organizations, including 114 US-based firms and victims in 68 other countries. Initial attacks targeted telecommunications companies to gather phone numbers used in MFA attacks. The ultimate goal was to access internal systems and facilitate supply-chain attacks. The campaign demonstrated how attackers can bypass MFA protections through phishing. Researchers recommend using FIDO2-compliant security keys and educating users about MFA attack methods to mitigate such threats.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 0ktapus threat group executed a sprawling phishing campaign that spoofed Okta's multi-factor authentication system to steal identity credentials and MFA codes from employees of over 130 organizations. The campaign began by targeting telecommunications companies to collect phone numbers, then sent phishing SMS messages containing links to fake Okta login pages. Victims submitted their credentials and MFA codes, enabling attackers to compromise 9,931 accounts. The attackers aimed to access company mailing lists and customer-facing systems to facilitate supply-chain attacks. The campaign affected primarily US-based firms but also victims in 68 other countries. The campaign highlights the ability of phishing attacks to circumvent MFA protections, emphasizing the need for stronger authentication methods such as FIDO2 security keys and user education on MFA attack vectors.
Potential Impact
The campaign compromised nearly 10,000 accounts across over 130 organizations, including 114 US-based companies and victims in 68 additional countries. Attackers obtained Okta credentials and MFA codes, enabling unauthorized access to internal tools and systems. In a related incident, DoorDash reported unauthorized access to internal tools and theft of personal information of customers and delivery personnel. The campaign demonstrates that MFA, while a strong security control, can be bypassed through sophisticated phishing attacks, leading to significant data breaches and potential supply-chain compromises.
Defensive Guidance
No official patch or fix applies as this is a phishing campaign rather than a software vulnerability. Researchers recommend using FIDO2-compliant security keys for MFA to provide phishing-resistant authentication. Additionally, organizations should educate users about common MFA attack techniques and how to recognize and respond to phishing attempts. Good hygiene around URLs and passwords is also advised. There is no indication that the threat has been fully mitigated or that no action is required.
Technical Details
- Classification
- {"confidence":0.59,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://threatpost.com/0ktapus-victimize-130-firms/180487/","fetched":true,"fetchedAt":"2026-08-04T12:41:21.935Z","wordCount":910}
Threat ID: 6a71ddf3bf8831d539cc9781
Added to database: 08/04/2026, 12:41:23 UTC
Last enriched: 08/04/2026, 12:42:22 UTC
Last updated: 09/13/2026, 21:38:33 UTC
Views: 50
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.