The Okta HAR Hijacking episode artwork

EPISODE · Dec 7, 2025 · 29 MIN

The Okta HAR Hijacking

from The CISO Signal: True Cybercrime Podcast · host Jeremy Ladner

In late 2023, the world’s most trusted identity provider experienced the kind of breach it was designed to prevent. Attackers quietly infiltrated Okta’s customer support system, stole session tokens hidden inside HAR files and used them to impersonate users across some of the most secure organizations on earth.For two full weeks, the intruders operated in silence. No alerts. No red flags. No detection.When the truth came out, it wasn't just a security incident, it was a crisis of trust in the infrastructure that underpins modern authentication.How did a company synonymous with identity become a cautionary tale? What does this breach reveal about session tokens as the new crown jewels, third-party risk, and the blind spots that even top-tier security teams can miss? And what lessons does every CISO need to take from the Okta compromise before history repeats itself?In this episode of The CISO Signal: True Cybercrime Podcast, host Jeremy Ladner is joined by Oren Zenescu, CISO at Plarium, to break down every layer of the Okta breach, from the silent entry and token theft to the fallout across the cybersecurity community and what it means for the future of identity security.💡 In this episode, we discuss:🔹 How attackers harvested HAR files and hijacked live session tokens🔹 Why session tokens are becoming the primary target for modern attackers🔹 The two-week detection delay and what it says about support system security🔹 What the Okta breach means for zero trust, vendor reliance, and third-party risk🔹 Lessons CISOs must take from Okta’s incident history Lapsus$, source code theft, and beyond🎙 Featured GuestOren Zenescu | Global CISO at PlariumMember of Team8 CISO Village, with 15+ years of enterprise security leadership across finance, gaming, and global tech.Follow The CISO Signal🌐 Website: thecisosignal.transistor.fm🔗 LinkedIn: linkedin.com/company/the-ciso-signalSubscribe & share to stay ahead of the world’s most sophisticated cyber threats.#CyberSecurity #OktaBreach #IdentitySecurity #TokenHijacking #ZeroTrust #CISO #IncidentResponse #SupplyChainSecurity #CyberCrime #TheCisoSignal

NOW PLAYING

The Okta HAR Hijacking

0:00 29:34

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of The CISO Signal: True Cybercrime Podcast?

This episode is 29 minutes long.

When was this The CISO Signal: True Cybercrime Podcast episode published?

This episode was published on December 7, 2025.

What is this episode about?

In late 2023, the world’s most trusted identity provider experienced the kind of breach it was designed to prevent. Attackers quietly infiltrated Okta’s customer support system, stole session tokens hidden inside HAR files and used them to...

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this The CISO Signal: True Cybercrime Podcast episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!