0ktapus Phishing Campaign Hits 130 Companies, Compromising Nearly 10,000 Accounts
A phishing campaign exploiting Okta's authentication system has breached 9,931 accounts across 130 organizations, with Twilio, Cloudflare and DoorDash among the victims.

Key points
- 0ktapus hackers breached 9,931 accounts across 130 companies.
- Attackers stole Okta credentials and 5,441 MFA codes via text-message phishing.
- Affected companies include Twilio, Cloudflare and DoorDash.
- 114 of the targeted firms were US-based, with victims across 68 other countries.
- Researchers recommend FIDO2-compliant security keys to resist this class of attack.
A phishing campaign called '0ktapus' has compromised accounts at more than 130 organizations by targeting employees through fake versions of their company's Okta login pages. Okta provides identity and access management services, handling the login and multi-factor authentication (MFA) flows that many large firms rely on. The breach figures come from cybersecurity firm Group-IB, whose report was first covered by Threatpost. Our earlier story on help desks being talked out of MFA resets showed the same weak point being hit from a different angle.
Attackers sent phishing text messages to employees, directing them to spoofed Okta pages where victims entered their credentials and MFA codes. Those codes, normally a second barrier to entry, were captured in real time. In all, 5,441 MFA codes were taken.
How did the hackers get in?
Group-IB's researchers believe 0ktapus first targeted mobile operators and telecommunications companies to collect phone numbers, then used those numbers to send phishing links. The links led to pages mimicking the Okta authentication page each target's employer used. Credentials went straight to the attackers.
The endgame wasn't just stolen passwords. Access to company mailing lists and customer-facing systems positioned the group for supply-chain attacks, where one compromised vendor becomes a doorway into its clients.
Roberto Martinez, senior threat intelligence analyst at Group-IB, told Threatpost the full scale may not be known for some time. That's a reasonable hedge: 114 US firms were confirmed, with victims scattered across 68 additional countries.
Should you worry about MFA being bypassed?
Yes, if your MFA relies on codes sent by text or entered through a browser prompt. Group-IB's report is direct on this: attackers overcame those controls with relatively simple tools. Roger Grimes, data-driven defense evangelist at KnowBe4, put it plainly in a statement via email: moving users from phishable passwords to phishable MFA delivers no real security gain if they're never taught what attacks against their MFA type look like.
Within hours of Group-IB publishing its report, DoorDash disclosed that an unauthorized party had used stolen vendor credentials to reach internal tools, taking customer names, phone numbers and delivery addresses. The timing and method fit the 0ktapus pattern.
Group-IB recommends switching to FIDO2-compliant hardware security keys for MFA. Unlike code-based methods, FIDO2 keys are bound to the legitimate domain and can't be relayed to a spoofed page. That's the practical fix, and it's the one worth pushing to any organization still running SMS or app-based one-time codes.



