Open cardosec

Case F64BAE · Famous breaches · L3 Applied

Screenshots from your support vendor

Practise as: Incident drill · Interview

Live alertMarch 2022, you are Okta's security lead. Lapsus$ posts screenshots of your internal admin tools, taken in January from a laptop of a support engineer at your outsourced vendor, Sitel.

Interview questionHow do you respond, both technically and in communications?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Establish facts: Sitel engineer's machine accessed via RDP for about 5 days in January; what could that role do?
  2. Scope by role permissions and audit logs: support could reset passwords/MFA but not download customer databases
  3. Notify affected customers fast; Okta was criticised for a 2-month delay and initially cited up to 366 tenants
  4. Final finding: 2 customer tenants actually accessed; forensics depended on getting Sitel's report quickly
  5. Lessons: third-party access in scope for IR, contractual forensic rights, least-privilege support tooling

If the interviewer pushes back

  • Lapsus$ used MFA fatigue, SIM swaps and bribing insiders. Which controls address each?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.