Microsoft confirms that the LAPSUS$ extortion-focused hacking crew gained “limited access” to its systems. Microsoft’s Threat Intelligence Center says no customer code or data was involved in the observed activities. Identity and access management company Okta also acknowledged the breach through the account of a customer support engineer working for a third-party provider. Okta said that the attackers had access to the engineer’s laptop during a five-day window between January 16 and 21, but that the service itself was not compromised. The attackers also claimed that Okta was storing Amazon Web Services (AWS) keys within Slack.”]
Source: https://thehackernews.com/2022/03/microsoft-and-okta-confirm-breach-by.html