Skip to content
KEDBYTE
How Identity Works
Chapter
58

Breaches That Taught Us Something

Part V · Identity, Society and the Law|13,755 words|about 60 min read|Volume 5
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

58.0 What this chapter gives you#

  1. You will be able to narrate the 2015 OPM intrusions in order, name the two intruders that investigators labelled X1 and X2, and explain why the remediation of 27 May 2014 removed one and not the other.
  2. You will be able to say what was stolen from OPM, in what quantities, and explain why 5.6 million sets of fingerprints are a different kind of loss from 21.5 million Social Security numbers.
  3. You will be able to draw the Equifax timeline from the Apache Struts disclosure of March 2017 to the settlement of July 2019, with the correct dates, vulnerability identifier and figures for records, databases and queries.
  4. You will be able to explain why one expired certificate on a traffic-inspection device turned a detectable intrusion into a 76-day undetected one, and what that says about having a control versus having a working control.
  5. You will be able to describe the two Okta incidents of 2022 and 2023 separately and accurately, say what a HAR file is, and explain why a session token inside a support attachment is as good as a password to whoever finds it.
  6. You will be able to state what encryption did and did not protect in the LastPass theft of 2022, including which vault fields were left in the clear and why a key derivation iteration count suddenly mattered to hundreds of thousands of people.
  7. You will be able to explain a signed-update compromise in identity terms, describe the golden SAML technique that followed SolarWinds, and name the log events a defender would look for.
  8. You will be able to explain why the MGM and Caesars incidents of September 2023 belong in an identity book, and describe the help desk as an authentication mechanism with a measurable failure rate.
  9. You will be able to separate, in the Aadhaar disclosure claims, what has been demonstrated from what has only been asserted, and defend the distinction with named reports and dates.
  10. You will be able to score any breach report against an explicit list of root causes, count them, and predict which controls a regulator or a vendor will change next.

Every control described in this book has a birthday. Somebody argued for it, somebody else said it was too expensive, and then something happened to real people on a real date and the argument ended. Phishing-resistant authentication is not an abstract preference; it is what several organizations wished they had on 8 August 2022. Session binding is not a product feature invented by a marketing department; it is what Okta shipped for administrator accounts after a stranger used a customer’s own diagnostic file to walk into that customer’s tenant. The rule that you must not store the key beside the thing it encrypts is not a maxim from a textbook; it is the difference between a stolen backup being noise and a stolen backup being a catastrophe, and LastPass discovered which side of that line it was on in late 2022.

This chapter is a set of case files. Nine of them, told carefully, with the numbers checked against primary sources rather than against the retellings that have accumulated around them. The retellings are usually wrong in small ways that matter. The Equifax certificate was not expired for nineteen months in the account the Government Accountability Office gives; it was about ten months. The “Big Bang” that was supposed to expel the intruders from OPM happened in 2014, not 2015, and that single year makes the whole story make sense. Okta’s October 2023 incident was not one disclosure but three, each larger than the last, and the shape of that escalation is itself one of the lessons.

Chapter 57 dealt with what happens to a person after their identity is stolen; chapter 59 takes every decision in this book and makes it explicit as a design exercise. This chapter sits between them and does one job: it establishes that the design decisions of chapter 59 are not preferences, but scar tissue. Read what follows as accident reports in the aviation sense. It is cheap to conclude that the people involved were careless; mostly they were engineers working inside organizations whose incentives, budgets and inherited systems made the failure likely and the fix hard. The Equifax engineer who did not patch a server was not on the mailing list that would have told him to. The point is the causal chain, not the culprit.

The plain version#

Rules written in someone else’s loss#

Look at the doors of any cinema or theatre you have been in. They open outwards, and they carry a horizontal bar at waist height that opens the door when you push against it with your body. You do not need a hand free. You do not need to know how the door works. You can be carried into it by a crowd and the door will open.

That bar exists because on 30 December 1903 a fire started in a theatre in Chicago and more than six hundred people died, many of them crushed against doors that opened inwards and were fastened with latches a panicking crowd could not operate. The rule that followed was not written by someone thinking hard in an office about crowd dynamics. It was written after the bodies were counted.

Nearly every safety rule you can point at has this shape: cockpit doors, medicine bottle caps, the height of stair railings, the fact that a lift will not move with its door open. Each is the fossil of a specific bad day, and each looks like fussy over-engineering right up until the moment it saves you, when it looks obvious. The rules in the rest of this book are the same kind of rules. Someone lost something specific, and a rule appeared. This chapter is the list of the losses.

Nine bad days#

Here are the nine, told in plain words with no special vocabulary. We will do all of them properly, with exact figures, later on.

The government files. An American government office keeps the paperwork for security clearances. To get a clearance you fill in a very long form about your whole life: every address, every foreign trip, every relative, every debt, every therapist, every arrest, and the names of people who know you well. Between 2014 and 2015 intruders took those files for 21.5 million people, along with 5.6 million sets of fingerprints. The office noticed one intruder, threw them out, and did not notice that a second had walked in three weeks before the eviction and stayed another year.

The credit bureau. A company whose entire business is holding files on people who never chose to be its customers ran a website with a flaw in it. The flaw had been publicly announced, and a patch existed, but the company could not find which of its own machines were affected. Someone got in, wandered from three databases to fifty-one, and took data out slowly for seventy-six days. Nobody saw it, because the device that was supposed to watch the traffic had a certificate that had run out and so it was, in effect, switched off.

The identity company, twice. A company that sells the front door for thousands of other companies had a bad January in 2022: someone took over the computer of a support worker at an outsourced help desk and for twenty-five minutes could act on customer accounts. Then it had a bad autumn in 2023: someone read the diagnostic files customers had uploaded when reporting a problem. Those files contained the equivalent of the customers’ own house keys, still warm.

The password vault. A company that keeps everyone’s passwords in an encrypted box had its box stolen. Not the passwords in the clear; the box. The trouble was threefold. The list of which websites each person had an account with sat outside the box, so it could be read. The box’s strength varied from customer to customer, depending on a setting most had never heard of. And for one other stolen box the key was taken too, because it had been sitting next to it.

The signed update. A company sells software that watches networks. Its build system was tampered with, so the update it shipped contained a hidden extra. The update was correctly signed, so every customer’s computer accepted it. Around 18,000 organizations installed it. Once inside a few of them, the intruders stole the thing that lets an organization write its own passes for its own staff, and wrote passes for themselves.

The casinos. In September 2023 two large casino groups were attacked within days of each other by people who did not break any cryptography and did not find any software flaw. They telephoned the help desk, said they were an employee who had lost their phone, and asked for the second factor to be reset. It was reset.

The national identity number. India has a twelve-digit number tied to fingerprints and iris scans, held for well over a billion people. Over a decade there have been many claims of catastrophic leaks. Claims about the central database were not shown to be true. Claims about the hundreds of ordinary government systems that had copied the number into their own spreadsheets and published them were true.

The health claims clearing house. In February 2024 a company that sits in the middle of American medical billing was entered using a stolen username and password on a remote access service that had no second factor switched on. The final count of affected people, filed with the health regulator, was 192.7 million.

The phishing week. In August 2022 a single campaign sent text messages to employees of more than a hundred companies, inviting them to a login page that looked exactly right. Nearly ten thousand accounts were taken. At one company three employees typed their password into the fake page, and nothing happened, because that company had given every employee a small hardware key and the key refused to work on a website with the wrong address.

The thing that cannot be reissued#

Stop on the fingerprints for a moment, because this is the single most important idea in the chapter and it does not need any technical vocabulary at all.

If someone steals your bank card, the bank sends you a new one. The card number changes. The old number is dead. The theft cost you a fortnight of inconvenience.

If someone steals your password, you change it. The old one is dead.

If someone steals your Social Security number or your national identity number, you cannot change it. Not easily, not in most countries at all. The number was designed to be permanent, because permanence is what makes it useful for joining up records over a lifetime. Permanence and revocability are opposites. You cannot have a number that is both a stable lifetime key and a thing you can cancel when it leaks.

And if someone steals your fingerprints, there is no procedure at all. You have ten. They do not change. They will still be yours in forty years, and so will the copy the thief has. A password is a fact about now. A fingerprint is a fact about your body, for life.

This is why the 5.6 million fingerprints matter more than the 21.5 million forms, even though the forms are four times as numerous, and why the honest response to a biometric theft is not “we will reissue” but “that method is now permanently weaker for those people”. A control that cannot be reset after a failure is a control with one life.

Counting the causes rather than admiring the damage#

If you read nine accident reports you notice something. The damage is always different and the causes are always the same: nine companies, nine industries, nine sets of stolen things, and the same handful of underlying mistakes in different costumes.

So instead of nine separate lessons, write down a short list of underlying causes, go through the nine cases, and tick which causes were present in each. At the end you have a count, and a cause appearing in eight cases out of nine deserves eight times the attention of one appearing once.

We will do that properly in the technical half, with a table and an honest note about where the scoring is a judgement call. In plain words, the eight causes are these.

A credential anybody can carry: a password, a code from an app, a cookie sitting in a file, where whoever holds it is treated as the person and nothing ties it to a particular piece of hardware in the real owner’s hand. A person used as a lock: somewhere in the process, a human being decides over the telephone whether you are who you say you are, under time pressure, measured on how quickly they resolve the call. Someone else inside your fence: a contractor, an outsourced support desk, a supplier’s software, a downstream government portal, all outside your organization but inside your trust. A known hole nobody closed: not an exotic discovery but a published flaw with a published fix, sitting on a machine nobody knew they owned.

Being unable to see: no logging, no alerting, a monitor with an expired certificate, a support system nobody watched. In every one of our nine cases the gap between intrusion and discovery was long, and in several the victim was told by somebody else. Too much access lying around: one account, server or person able to reach far more than the job requires, so that a single compromise becomes a total one. The key next to the lock: encrypted data and its decryption key in the same stolen bundle, or plain-text passwords in a file on the same network as the databases they open. And a name used as a secret: a Social Security number, a national identity number, a mother’s maiden name, a date of birth. These are labels for a person, never secrets, and a system that treats knowing the label as proof of being the person guarantees that a leak of labels becomes a wave of impersonation.

Nothing in that list is clever. That is exactly the point. The catastrophes in this chapter cost billions of pounds between them and not one of them required the attacker to break a cipher.

Where the plain version stops being true#

The accident report is not the accident#

The plain version implies that we know what happened. Mostly we know what was written down afterwards, by people with interests.

The honest version: almost every figure in this chapter is a reconstruction, produced under legal supervision, months after the event, from logs never designed to answer the question being asked of them. When Equifax told the Government Accountability Office that the attackers ran approximately 9,000 queries, that number came from log files that happened to record queries. Configured differently, the number would differ; configured badly, there would be no number. Dwell times, record counts and “no evidence of misuse” statements describe the quality of the victim’s instrumentation as much as the attacker’s behaviour.

This is why “no evidence of unauthorized access” is one of the least informative sentences in the language. It is true of an organization that looked hard and found nothing, and equally true of one with no logs at all. Ask the follow-up: what would evidence have looked like, and would you have had it.

Which report you read changes the number#

The plain version gave single figures. The primary sources do not always agree, and the disagreements are instructive rather than embarrassing.

Take the Equifax certificate. The Government Accountability Office report GAO-18-559, published in August 2018, says the certificate on the traffic-inspection device had expired about ten months before the breach. The United States Senate Permanent Subcommittee on Investigations staff report of March 2019 says the certificate for the online dispute portal had been expired since November 2016 and was replaced on the night of 29 July 2017, and that this delayed detection by seventy-eight days. Both are defensible; they are counting slightly different things over slightly different windows, and one is describing the device’s certificate and the other the application’s. If you cite “nineteen months”, which circulates widely, you are citing a third figure that appears in yet another account, and you should say which.

The lesson is not that the sources are unreliable, but that a breach has no single canonical number, and a writer who gives you one without naming the document has not read the documents.

“The database was not breached” can be true and useless#

Several organizations in this chapter responded to disclosure claims by saying that their central database had not been breached. In at least some cases that statement appears to be correct and it is also, on its own, close to meaningless.

The honest version: an identity system is not its central database. It is the central database plus every system that has ever been given a copy of anything from it. If a national identifier has been copied into ten thousand government portals, bank onboarding systems, telecommunications subscriber records, employer files and shopkeepers’ notebooks, then the security of that identifier is the security of the least careful of those ten thousand, not the security of the vault at the centre.

So “our core system was not compromised” is a claim about a small part of the risk surface. It can be true and, at the same time, irrelevant to the person whose data is being sold. Organizations that say only that half are managing their reputation rather than informing you.

Encryption is not a switch#

The plain version said the password vault was “an encrypted box”. Encryption in a real product is never one box. It is a set of decisions, field by field, about what is encrypted, with which key, derived how, held where.

In the LastPass case the same stolen backup contained website addresses in the clear and the usernames and passwords for those websites under AES-256. That was a deliberate product decision made years earlier, presumably so that the service could show you a site icon or match a login form without decrypting. It was defensible when it was made and disastrous when the backup walked out of the door, because the list of which sites a person has an account with is itself extremely valuable to a targeted attacker.

The honest version: whenever you read that data was “encrypted”, ask three questions. Which fields, under whose key, and where was the key when the data was taken. In one part of that same incident the answer to the third was “in the same stolen bundle”, and there the encryption bought nothing.

The headline number is a claim, not a measurement#

The plain version said an Indian dataset of 815 million records was offered for sale. That is accurate as a description of what a criminal advertised. It is not a measurement of anything.

What was actually demonstrated, according to the security firm that investigated in October 2023, is that the seller published sample files totalling about 400,000 records, that a portion of those records checked out against the official verification service, and that people contacted at random confirmed their own details. Everything beyond that -- the total of 815 million, the source of the data, the claim that any particular organization was the origin -- was assertion.

The honest version: a breach claim has three separable parts, and you should always split them. Volume, provenance and validity. Validity can be tested on a sample. Volume usually cannot be tested at all. Provenance is often unknowable from outside and is the part most likely to be wrong in press coverage, because a criminal has every incentive to name an impressive source and no incentive to name a boring one.

Root causes are not independent, and counting them overstates the arithmetic#

We are about to count causes across nine incidents and present a tidy table. Be sceptical of your own table.

The eight causes overlap. “Too much access lying around” and “someone else inside your fence” are not independent: outsourced staff have excessive access precisely because provisioning them narrowly is expensive. “Being unable to see” is present in nine cases out of nine, which is suspicious: it may be less a cause than a definitional consequence, since an intrusion detected immediately rarely becomes a breach worth reporting. That is survivorship bias inside the data set, and it means the count describes the population of published reports rather than of attempted attacks.

The honest version: the tally is a device for directing attention, not a statistical result. Trust it for the ordering of the large effects. Do not trust it for any difference of one.

The rule that follows a disaster was not always caused by it#

It is tempting to draw a straight line from every incident to every subsequent standard. Real causation is messier. Phishing-resistant authentication did not begin with the casino attacks of 2023: the W3C published Web Authentication as a recommendation in March 2019, and the federal memorandum requiring phishing-resistant methods across United States agencies, OMB M-22-09, is dated 26 January 2022, a year and a half before those attacks. What incidents change is not usually the existence of a control but its priority, its default setting, and the willingness of a budget-holder to fund it.

So when this chapter says “what each incident changed”, read it as what appeared, or was accelerated, or became a default afterwards, with dates given so that you can judge the connection yourself. Two of the changes below are direct and documented. Most are the acceleration of something already in motion.

The technical version#

OPM 2015: two intruders, one eviction, and data that cannot be reissued#

The United States Office of Personnel Management is the human resources agency of the federal government, and it holds the results of background investigations for security clearances. The evidence base is the Standard Form 86, the questionnaire for national security positions, which runs to well over a hundred pages of adjudicative detail: residences, employment, foreign contacts, foreign travel, financial delinquency, drug and alcohol history, psychological treatment, police records, and the names and addresses of references and relatives.

The intrusions were two, and the investigators distinguished them. The Department of Homeland Security labelled the first adversary X1 and the second X2.

X1 was discovered on 20 March 2014, when a third party notified the department that data was leaving OPM’s network. OPM and its partners watched the adversary rather than evicting it at once, and planned a coordinated remediation that the House Oversight Committee’s report calls the Big Bang: a mass reset and disconnection intended to remove the foothold in one stroke. It was executed on 27 May 2014, prompted by the adversary starting to load keyloggers onto database administrators’ workstations.

The Big Bang worked, in that X1 was expelled. It also failed, in the single most instructive way in the whole case. On 7 May 2014, twenty days before the eviction, a second adversary had entered using credentials belonging to an employee of KeyPoint Government Solutions, a contractor performing background investigations. X2 was not in the remediation plan because nobody knew X2 existed, and the eviction of X1 gave the agency confidence that the problem was solved. X2 remained inside until 15 April 2015, when it was found during the evaluation of a commercial endpoint detection product.

Write that sequence down as a table, because the ordering is what most retellings get wrong.

Date Event
20 Mar 2014 X1 exfiltration reported
7 May 2014 X2 enters, contractor login
27 May 2014 Big Bang evicts X1 only
15 Apr 2015 X2 finally discovered
4 Jun 2015 Personnel records announced
9 Jul 2015 21.5 million confirmed
23 Sep 2015 Fingerprints revised to 5.6m

The published totals are as follows. The personnel records incident affected approximately 4.2 million current and former federal employees. The background investigation incident affected 21.5 million individuals, comprising 19.7 million who had applied for an investigation and 1.8 million non-applicants, predominantly spouses and cohabitants of applicants. Across both, the government put the total at 22.1 million people. On 23 September 2015 OPM revised the fingerprint count from 1.1 million to 5.6 million, an upward revision by a factor of five, five months after the discovery.

That last figure is the one to hold on to. A Social Security number cannot practically be reissued. A fingerprint is worse: not merely permanent but biological, and not remediable by any administrative act. If a cleared officer’s fingerprints are in an adversary’s hands, then every future situation in which those prints are taken -- a border crossing, a visa application, a hotel registration in some jurisdictions -- becomes a potential identification event, for life. The 1.8 million non-applicants are the second uncomfortable detail: those people never applied for anything. They were named on somebody else’s form.

The Committee on Oversight and Government Reform published its staff report on 7 September 2016 under the title “The OPM Data Breach: How the Government Jeopardized Our National Security for More than a Generation”. Its findings were blunt: the breach was preventable; OPM’s leadership had disregarded repeated guidance from its own Inspector General; the 2014 and 2015 events were connected and possibly coordinated; and the agency had given inaccurate information to the public and incorrect statements to Congress. Among its recommendations, and this is worth noting given the date, was to reprioritize federal information security toward zero trust -- an architectural stance in which no network location is trusted by default and every request is authenticated and authorized on its own merits. That recommendation is from 2016, five and a half years before the federal zero trust memorandum of January 2022.

The director of OPM, Katherine Archuleta, resigned on 10 July 2015, the day after the 21.5 million figure was announced. The chief information officer, Donna Seymour, resigned on 22 February 2016. The class action litigation, brought against OPM and its background investigation contractor, settled for $63 million, with final approval granted by a federal judge in the District of Columbia in October 2022 -- seven years after the announcement, which is a useful figure to keep in mind when anyone tells you that litigation is a rapid corrective.

What changed. The federal Cybersecurity Sprint of June 2015 pushed agencies to enforce use of the Personal Identity Verification card, the hardware smart card mandated under Homeland Security Presidential Directive 12, for privileged users. The direction of travel from there runs through the Cybersecurity Strategy and Implementation Plan, the Federal Cybersecurity Enhancement Act of 2015, and eventually Executive Order 14028 of 12 May 2021 and the zero trust memorandum M-22-09 of 26 January 2022, which requires agency staff to use phishing-resistant methods and explicitly names the PIV standard and the W3C Web Authentication standard as acceptable.

One loose end is worth flagging rather than papering over. Unlike the Equifax case, which produced a named indictment in 2020, the OPM intrusions have not, to my knowledge, produced a public United States prosecution of the intruders themselves, though prosecutions related to malware used in intrusions of that period did occur. [UNVERIFIED: whether any individual has been publicly charged in the United States specifically for the OPM intrusions, as opposed to related malware activity]

Equifax 2017: a published patch, an expired certificate, and 76 days#

Equifax is a consumer credit reporting agency. Its subjects are not its customers; they cannot decline the relationship. That asymmetry is why this case attracted the legislative response it did.

The vulnerability was CVE-2017-5638, a remote code execution flaw in the Jakarta Multipart parser of Apache Struts 2, a Java web application framework. A crafted Content-Type header could cause the parser to evaluate an expression, giving the sender the ability to run commands on the server. The Apache Software Foundation disclosed it and published a fix in early March 2017. According to GAO-18-559, the United States Computer Emergency Readiness Team publicly identified the vulnerability two days before 10 March 2017, which places the alert on 8 March 2017.

On 10 March 2017, unidentified individuals scanned Equifax’s systems for the flaw, found the server hosting the online dispute portal -- a web application that lets a consumer upload documents to contest an inaccuracy in their credit file -- and confirmed that they could run commands. GAO records that no data was taken at that point.

Then, in what GAO describes as a separate incident, attackers gained access beginning on 13 May 2017 and started to extract data. The internal geography of what followed is the part practitioners should study.

Equifax intrusion, as described in GAO-18-559
--------------------------------------------
  [ Internet ]
       |
       |  CVE-2017-5638 in Apache Struts 2
       v
  [ Online dispute portal ]  <- 3 databases here
       |
       |  found file with plain-text usernames
       |  and passwords
       v
  [ 48 further, unrelated databases ]
       |
       |  approx. 9,000 queries run
       v
  [ Data removed in small increments ]
       |
       |  encrypted channel, uninspected because
       |  the inspection device's certificate
       |  had expired
       v
  [ 76 days of undetected extraction ]

Each arrow is a control that was absent. The portal was reachable from the internet running unpatched software, because Equifax’s scanning did not identify the vulnerable version, and, as the Senate subcommittee recorded, the developer who knew the company ran Struts was not on the distribution list carrying the alert. The three databases behind the portal were not isolated from the other forty-eight. The credentials permitting lateral movement were stored unencrypted. And the traffic inspection device that would have seen the exfiltration was passing encrypted traffic uninspected because of a misconfiguration caused by an expired digital certificate -- expired, GAO says, about ten months before the breach.

The discovery on 29 July 2017 happened because staff performing routine checks installed new certificates and immediately began seeing the traffic that had been invisible for months. The portal was taken offline on 30 July 2017. The chief executive was informed on 31 July. Public announcement came on 7 September 2017, six weeks after the internal discovery.

The final figures, and note carefully which source gives which:

Item Figure Source
Individuals affected 145.5m at least GAO-18-559
Individuals affected approx. 147m FTC, Jul 2019
Databases reached 51 GAO-18-559
Queries run approx. 9,000 GAO-18-559
Credit card numbers approx. 209,000 GAO-18-559
Dispute documents approx. 182,000 GAO-18-559
Extraction window 76 days GAO-18-559

The count moved twice. GAO records that in late September 2017 Equifax determined it had wrongly concluded that one of the attackers’ queries returned no data; on re-analysis that query had exposed approximately 2.5 million further consumers.

The consequences. On 22 July 2019 Equifax entered a global settlement with the Federal Trade Commission, the Consumer Financial Protection Bureau and fifty states and territories, agreeing to pay at least $575 million and potentially up to $700 million, with up to $425 million available to consumers. On 10 February 2020 the Department of Justice announced a nine-count indictment of four members of the People’s Liberation Army’s 54th Research Institute -- Wu Zhiyong, Wang Qian, Xu Ke and Liu Lei -- for the intrusion.

What changed, concretely and datably: on 21 September 2018 the Economic Growth, Regulatory Relief, and Consumer Protection Act took effect in the United States, making security freezes on credit files free nationwide and extending fraud alerts to a year. Before that date, in many states, protecting yourself from the consequences of a breach you had no part in cost you a fee per bureau. That is as direct a line from an incident to a statutory change as this chapter contains.

The identity lesson is separate from the security one. The data taken was exactly the data used as answers to knowledge-based verification questions: former addresses, loan amounts, vehicle purchases. An industry had built identity proofing on the assumption that this information was hard to obtain, and after 2017 that assumption was indefensible. The NIST Digital Identity Guidelines had already moved against knowledge-based verification in the SP 800-63-3 revision of June 2017.

Okta 2022 and 2023: when the front door provider is the blast radius#

Okta sells identity as a service. Its customers point their staff and their applications at Okta and let Okta decide who is who. That business model means an incident at Okta is not one company’s incident.

The January 2022 event began at 23:18 UTC on 20 January 2022, when Okta’s security team was alerted that a new multi-factor authentication factor had been added to the account of a support engineer from a new location. The engineer worked for Sitel, an outsourced customer support provider. The incident was escalated at 23:46 UTC, and the account was suspended with sessions terminated at 00:28 UTC on 21 January. Indicators were shared with Sitel at 18:00 UTC the same day, and Sitel engaged a forensic firm.

Then the timeline stops moving. The forensic investigation completed on 28 February 2022, the report was dated 10 March, and Okta received a summary on 17 March. On 22 March 2022 at 03:30 UTC the group calling itself LAPSUS$ posted screenshots publicly; Okta linked them to the January incident at 05:00 UTC and received the complete forensic report at 12:27 UTC, after the screenshots were public.

Okta’s conclusion was that the maximum potential impact was 366 customers, approximately 2.5 percent of its customer base, being every tenant any Sitel engineer could have touched in the window. The actual finding was narrower: the threat actor controlled a single Sitel workstation for 25 consecutive minutes on 21 January 2022, and two customer tenants were accessed.

The gap between 366 and 2 is the story. In the fifty-nine days between detection and disclosure, every one of those 366 customers was in an unknown state and could not tell which. On the technical merits the containment was fast. The lesson is that in a federated identity system uncertainty propagates faster than facts, and a disclosure process measured in weeks is incompatible with a compromise measured in minutes.

The October 2023 event is a different failure with a sharper technical edge. From 28 September to 17 October 2023, a threat actor had access to files in Okta’s customer support case management system. The root cause, published on 3 November 2023, was mundane: an employee signed into their personal Google profile in Chrome on a company laptop, and the credentials for a service account were saved into that personal Google account. Okta’s assessment is that the most likely exposure route was compromise of the employee’s personal account or personal device.

What made it damaging was what customers had uploaded. When a support engineer needs to debug a browser-side problem, a common request is for an HTTP Archive file, usually written with the extension .har. A HAR file is a JSON recording of everything the browser sent and received, including request headers. Request headers include cookies. Cookies include session tokens.

{ "log": { "entries": [ {
  "request": {
    "method": "GET",
    "url": "https://example.okta.com/api/v1/users",
    "headers": [
      { "name": "cookie",
        "value": "sid=102...REDACTED...ab; JSESSIONID=..." },
      { "name": "user-agent", "value": "Mozilla/5.0 ..." }
    ]
  },
  "response": { "status": 200 }
} ] } }

That sid value is a bearer token: whoever presents it is the session. It is not tied to a device, a key or a person. A support attachment therefore contained, in effect, a live administrative session for the customer who uploaded it.

BeyondTrust’s published account gives the timing that makes this concrete. A support engineer asked a BeyondTrust administrator to upload a HAR file. Within thirty minutes of the upload, an attacker used the session cookie inside it. The first attempt to reach the administrative console from a Malaysian address was blocked by BeyondTrust’s own policy, which required Okta Verify on a managed device for console access. The attacker then pivoted to the Okta API, where that policy did not apply, and created a service account named svc_network_backup for persistence. BeyondTrust’s own detection caught it and disabled the account.

BeyondTrust alerted Okta on 2 October 2023, requested escalation on 3 October, held calls on 11 and 13 October, and received confirmation from Okta’s security leadership on 19 October, with public disclosure on 20 October. Okta’s own timeline shows the service account identified on 16 October using an IP indicator supplied by BeyondTrust on 13 October and disabled on 17 October, with a fifth affected customer, Cloudflare, identified on 19 October. 1Password had reported suspicious activity on 29 September, the day after the access began.

The scope then grew twice. On 3 November 2023 Okta said 134 customers, fewer than one percent, had a file accessed, and five experienced session hijacking. On 29 November 2023 Okta disclosed that the actor had also run and downloaded a report containing the names and email addresses of all Okta customer support system users; the report was run on 28 September 2023, and for 99.6 percent of users in it the only contact information held was full name and email address. Okta had more than 18,000 customers at the time. An initial “fewer than one percent” became, six weeks later, “everyone who has ever filed a support ticket”.

Between these two incidents sits Okta’s advisory of 31 August 2023, “Cross-Tenant Impersonation: Prevention and Detection”, which is the bridge to the casino section below. It describes threat actors socially engineering IT service desk staff into resetting all multi-factor factors on highly privileged accounts, then using Super Administrator privilege to grant themselves more, reset other administrators’ authenticators, and in some cases remove second-factor requirements from authentication policies. It also describes a subtler move: configuring a second identity provider as an impersonation application and manipulating the username parameter so that inbound federation logs the attacker in as a real user of the target organization.

What changed. Okta’s remediations after October 2023 were to disable the compromised service account, apply a Chrome Enterprise configuration preventing sign-in to personal Google profiles on managed laptops, add monitoring to the support system, and -- the durable one -- release session token binding based on network location for administrator accounts. The August 2023 advisory is the modern administrator baseline: phishing-resistant authentication using FIDO2 WebAuthn, re-authentication for sensitive administrative actions, zero standing privileges with custom admin roles, admin access restricted to managed devices and trusted networks, and session binding by network identifier.

LastPass 2022: what the ciphertext protected, and what it did not#

LastPass is a password manager. Its security model is that the vault is encrypted on your device with a key derived from your master password, and the company never sees the key. That model is sound. The 2022 incident is a case study in everything around the model.

There were two incidents, and the second used the first. In August 2022 an unauthorized party accessed the development environment through a compromised developer account and took portions of source code and proprietary technical information. LastPass initially and correctly said that no customer vault data was involved.

The second incident used information taken in the first. According to LastPass’s account of 1 March 2023, the actor targeted a senior DevOps engineer -- one of only four employees with access to the corporate vault holding the decryption keys for cloud storage -- by exploiting a vulnerable third-party media software package on the engineer’s home computer. That gave remote code execution, which allowed a keylogger to be implanted, which captured the engineer’s master password as it was typed after multi-factor authentication had been satisfied. Reporting in February 2023, citing a person briefed on LastPass’s private report, identified the media software as Plex; Plex disclosed its own separate intrusion on 24 August 2022. Threat actor activity in the second incident ceased on 26 October 2022.

What was taken from cloud storage was a set of backups, and the composition matters field by field.

Field State in the backup
Website URLs Not encrypted
Usernames AES-256 encrypted
Passwords AES-256 encrypted
Secure notes AES-256 encrypted
Form-fill data AES-256 encrypted
Account metadata Not encrypted
MFA/federation db Encrypted, key stolen

Read the first and last rows together. The unencrypted URL list tells an attacker which services each identified person uses: which bank, which exchange, which corporate portal. That is a targeting database even if not one password is ever cracked. And for the multi-factor and federation database backup, LastPass stated plainly that the separately stored decryption key was among the secrets stolen in the second incident -- so for that artefact, encryption provided no protection at all. Encryption protects you when the key is somewhere the attacker is not.

The remaining protection for vault contents is the key derivation function. LastPass derives the vault key from the master password using PBKDF2, a function deliberately made slow by repeating an internal operation many times so that guessing is expensive. LastPass stated that since 2018 it had required a twelve-character minimum master password and used 100,100 iterations of PBKDF2. The arithmetic of that choice became a public matter in December 2022, when independent analysts pointed out that the contemporaneous OWASP Password Storage Cheat Sheet recommendation for PBKDF2 with HMAC-SHA256 was 310,000 iterations, and that many long-standing accounts had never been migrated from far older, much lower settings. LastPass subsequently moved its recommended and default figure to 600,000 iterations, matching OWASP’s later raised recommendation.

Work the numbers, because this is the worked example that shows what an iteration count buys.

Guessing cost, illustrative
---------------------------
Assume an attacker can compute 1,000,000 PBKDF2-
HMAC-SHA256 single iterations per second per GPU
core-equivalent. (Order of magnitude only; real
rates depend on hardware and are always changing.)

At 100,100 iterations:
   guesses per second = 1,000,000 / 100,100
                      = 9.99  -> about 10 per second

At 600,000 iterations:
   guesses per second = 1,000,000 / 600,000
                      = 1.67  -> about 1.7 per second

Ratio = 600,000 / 100,100 = 5.99 -> about 6x slower

A 4-word passphrase from a 7,776-word list has
7,776^4 = 3.66e15 possibilities.
At 10 guesses/sec, exhausting it takes
   3.66e15 / 10 = 3.66e14 seconds
                = about 11.6 million years.

A password that is a common word plus 2 digits has
maybe 10,000 x 100 = 1,000,000 possibilities.
At 10 guesses/sec that is
   1,000,000 / 10 = 100,000 seconds
                  = about 1.2 days.

The point is not the exact rates, which change with hardware every year, but the shape. Raising the iteration count by a factor of six multiplies the attacker’s time by six. Choosing a passphrase instead of a word plus digits multiplies it by roughly three billion. The iteration count is the vendor’s contribution and it is linear; the entropy of the master password is the user’s and it is exponential. A vault theft converts every weak master password in the customer base into an offline guessing target, with no rate limiting, no lockout and no expiry, forever.

That is the honest summary of what encryption did and did not protect in this case. It protected the vault contents of customers with strong master passwords, indefinitely. It protected the vault contents of customers with weak master passwords for as long as it takes to run a wordlist, which is not long. It did not protect the list of sites anybody used. And where the key travelled with the ciphertext, it protected nothing.

SolarWinds: a signed update, and the golden ticket that followed#

SolarWinds Orion is network monitoring software. In 2020 its build process was compromised so that shipped updates carried a backdoor, known as SUNBURST. Because the malicious builds were signed with SolarWinds’ own legitimate code-signing certificate, every customer’s update mechanism accepted them as authentic. This is the identity failure at the heart of the case: the signature was valid, the publisher was genuine, and the verification logic behaved exactly as designed. Code signing answers the question “did this come from SolarWinds”, and the answer was yes.

The affected builds were narrow and specific: Orion Platform 2019.4 HF 5 (file version 2019.4.5200.9083), 2020.2 unpatched and 2020.2 HF 1 (file version 2020.2.5300.12432). SolarWinds stated in a filing with the Securities and Exchange Commission that approximately 18,000 of its roughly 300,000 customers ran affected versions. That is the number that gets quoted. The number that matters is smaller: GAO’s later review records SolarWinds estimating that fewer than 100 customers were actually compromised in the follow-on activity, and on 17 February 2021 Deputy National Security Adviser Anne Neuberger said nine federal agencies and about 100 private sector companies had been compromised. The backdoor was broad; the exploitation was selective.

The response was immediate and unusually forceful. CISA issued Emergency Directive 21-01, “Mitigate SolarWinds Orion Code Compromise”, on 13 December 2020. It required federal agencies to forensically image affected systems, immediately disconnect or power down affected Orion products, block external traffic to and from hosts running the software, identify and remove threat actor accounts, and report by noon Eastern on 14 December 2020 -- a deadline of less than a day. After removing the attacker’s mechanisms, agencies had to treat all hosts monitored by Orion as compromised, rebuild them and reset credentials. Supplemental guidance followed on 18 and 30 December 2020 and 6 January 2021, with supplemental direction on 22 April 2021.

Now the identity part, which is why this case belongs in this book rather than only in a supply chain one. CISA’s advisory AA21-008A, “Detecting Post-Compromise Threat Activity in Microsoft Cloud Environments”, first published on 8 January 2021 and updated on 15 April 2021 to attribute the activity to the Russian Foreign Intelligence Service, describes three components of the actor’s tradecraft: compromising or bypassing federated identity solutions, using forged authentication tokens to move laterally into Microsoft cloud environments, and using privileged cloud access to establish API-based persistence.

The specific technique is commonly called golden SAML. Active Directory Federation Services signs the assertions that tell a cloud service provider who a user is. Those assertions are signed with a token-signing certificate held on the ADFS server. An attacker with sufficient access to that server can extract the certificate and private key -- CISA’s detection guidance explicitly looks for Export-PfxCertificate and certutil -exportPFX in PowerShell event IDs 4103 and 4104, and for the named pipe used by tooling that dumps ADFS secrets. With the key, the attacker can mint an assertion for any user, with any claims, at any time. The service provider verifies the signature, finds it valid, and grants access. There is no authentication event on the domain controller because no authentication took place.

Normal federated sign-in
------------------------
 user -> ADFS -> signed assertion -> cloud service
          |
          +-- domain controller logs event 4769

Golden SAML
-----------
 attacker (holding stolen token-signing key)
          |
          +-- forges assertion for any user
                 |
                 v
             cloud service accepts it
          (no matching 4769 on the DC)

That asymmetry is the detection method. CISA’s guidance is to search for logins to service providers that have no corresponding event IDs 4769, 1200 and 1202 in the domain, to look for ADFS configuration change events 307 correlated with 510, and to pivot on the value 16457 in the unified audit log’s user authentication method field as a possible indicator of a forged token. It also recommends adding a custom element to SAML responses per service provider so that future irregular assertions stand out.

Two further consequences. The compromised code-signing certificate was revoked on 8 March 2021, a reminder that a private key held by a build system is a credential of the same class as a password, and that revoking it breaks every legitimate deployment too. And on 30 October 2023 the Securities and Exchange Commission charged SolarWinds and its Chief Information Security Officer, Timothy G. Brown, with fraud and internal control failures. A court dismissed most of the claims in July 2024; the Commission and the defendants filed a joint stipulation on 20 November 2025 dismissing the remainder with prejudice, recorded in SEC Litigation Release No. 26423. As of August 2026 that case ended without a finding against the defendants.

What changed. Executive Order 14028 of 12 May 2021 pushed software bills of materials and secure development practices into federal procurement, and NIST’s Secure Software Development Framework, SP 800-218, became the reference for what “secure development” means there. The narrower identity change was the hardening or retirement of on-premises federation servers holding long-lived signing keys, in favour of cloud identity providers with hardware-protected keys and shorter-lived credentials.

MGM and Caesars 2023: the help desk as an authentication mechanism#

In September 2023 two large casino and hotel groups were attacked by the same loose criminal community. Neither attack turned on a software vulnerability. Both turned on a telephone call.

Caesars Entertainment filed a Form 8-K on 14 September 2023 that begins with an unusually clear sentence: the company “recently identified suspicious activity in its information technology network resulting from a social engineering attack on an outsourced IT support vendor used by the Company”. The filing states that on 7 September 2023 Caesars determined the actor had acquired a copy of its loyalty programme database, including driving licence numbers and Social Security numbers for a significant number of members. Reporting on subsequent state breach notifications places the unauthorized access on 18 August 2023 and the data theft on 23 August 2023, with discovery on 7 September; one state filing recorded 41,397 residents of Maine affected. Press reporting, not the filing, put the ransom paid at approximately $15 million, reduced from an initial demand.

MGM Resorts International was attacked days later. Its Form 8-K of 5 October 2023 states that the criminal actors obtained, for some customers who had transacted with the company before March 2019, personal information including name, contact information, gender, date of birth and driving licence numbers, and that the company had determined on or around 29 September 2023 that this data had been obtained on 11 September 2023. The same filing estimates a negative impact from the September incident of approximately $100 million to Adjusted Property EBITDAR for the Las Vegas Strip Resorts and Regional Operations. In plain terms: hotel key cards, slot machines, booking systems and restaurant tills stopped working for days.

The technique is documented by the government. Joint advisory AA23-320A, released on 16 November 2023 and updated on 21 November 2023, describes the group as Scattered Spider, also tracked as Starfraud, UNC3944, Scatter Swine and Muddled Libra. Its listed techniques are precisely the ones an identity engineer must design against:

  1. Posing as company IT or help desk staff by telephone or SMS to obtain credentials.
  2. Sending repeated multi-factor push notifications until the target accepts one, a technique commonly called MFA fatigue.
  3. Persuading mobile carriers to transfer a target’s number to a SIM the attacker controls.
  4. Registering victim-specific domains of the form victimname-sso[.]com to host convincing login pages.

The advisory’s primary recommendation is phishing-resistant multi-factor authentication using FIDO or public key infrastructure.

The design lesson is worth stating starkly. In almost every organization the account recovery path is the weakest authentication path, and it is operated by people measured on call handling time and customer satisfaction. If a user can regain access by convincing a human being over the telephone, the security of that account is the security of that conversation, regardless of which authenticator is registered. Registering a hardware security key and leaving a telephone reset path open is fitting a deadbolt and leaving the key under the mat.

The corollary is that recovery must be designed with the same rigour as authentication: recovery via a second registered authenticator rather than a human decision; verification at recovery at least as strong as at enrolment; a mandatory delay and out-of-band notification on high-risk changes; and, for privileged accounts, no telephone-based recovery at all. Okta’s August 2023 advisory recommends exactly this pattern.

The regulatory context changed in the same season. The Securities and Exchange Commission adopted its cybersecurity disclosure rules on 26 July 2023. Item 1.05 of Form 8-K requires disclosure of a cybersecurity incident determined to be material, generally within four business days of the materiality determination, and Item 106 of Regulation S-K requires annual description of risk management processes and board oversight. Compliance with the Form 8-K requirement began on 18 December 2023, with an additional 180 days for smaller reporting companies. The Caesars and MGM filings predate the compliance date but read as previews of the regime.

MGM’s civil exposure resolved later: a $45 million settlement covering both the July 2019 and September 2023 incidents received final approval on 18 June 2025.

Aadhaar: separating what was shown from what was claimed#

Aadhaar is India’s national identity number: twelve digits, issued by the Unique Identification Authority of India, backed by ten fingerprints and two iris scans, and issued to well over a billion people. Because of its scale, claims about Aadhaar data attract attention out of proportion to their evidence, in both directions. The discipline this section applies is the one from earlier in the chapter: separate volume, provenance and validity, and say which of the three has actually been demonstrated.

Substantiated: downstream portals published the data themselves. On 1 May 2017 the Centre for Internet and Society published a report by Amber Sinha and Srinivas Kodali titled “Information Security Practices of Aadhaar (or lack thereof): A documentation of public availability of Aadhaar numbers with sensitive personal financial information”. It estimated 130 to 135 million Aadhaar numbers publicly available through four government portals. In a subsequent clarification the authors set out how the figure was derived: by adding beneficiary counts that the portals themselves published in their own management information reports -- 109,760,343 from the national rural employment guarantee scheme, 6,395,317 from the national social assistance programme, and 20,560,896 from a state insurance scheme. Nobody had to break anything. The numbers were on the web, next to names and bank account details, because the schemes published beneficiary lists for transparency and nobody had asked whether the identifier belonged in a transparency report.

This is the most important Aadhaar fact in the chapter, and it is not a breach at all in the conventional sense. It is a structural consequence of one identifier being copied into thousands of systems with different governance: the security of the identifier is the security of its least careful holder.

Contested: the 2018 access-for-sale report. On 4 January 2018 The Tribune published a report by Rachna Khaira describing the purchase, for 500 rupees, of access to a service that returned demographic details for any Aadhaar number, with a further 300 rupees for software to print a card. UIDAI denied that the biometric database had been breached and filed a first information report naming the newspaper and the reporter, a step that drew criticism from press freedom organizations. Both things can be true: the central biometric repository may not have been touched, and an unauthorized service may still have been reselling access granted through legitimate operator credentials. That is an access control failure at the edge, not a compromise of the centre, and the two are routinely conflated.

Mostly unsubstantiated: the 2023 dark web listing. On 9 October 2023 a seller on a criminal forum advertised 815 million “Indian Citizen Aadhaar and Passport” records. The security firm Resecurity, which investigated and published on 15 October 2023, reported the following: the seller asked $80,000 for the set; samples were posted on 9, 10, 11 and 13 October totalling roughly 400,000 records; the fields included name, father’s name, phone number, passport number, Aadhaar number, age, gender and address; Resecurity acquired the samples, validated a portion of them against the official verification facility, and contacted individuals who confirmed their details and said they had received no notification. The seller declined to state the source.

So: validity, demonstrated on a sample of about 400,000. Volume of 815 million, asserted only. Provenance, unknown; press reporting connected it to a medical research body’s test database, and Indian authorities opened an investigation, but the seller never stated a source and no confirmation was published. UIDAI’s consistent position has been that its central repository has not been breached.

Claim Status
130-135m via portals, 2017 Documented from portals
Rs 500 access service, 2018 Reported; UIDAI denied
400,000 records valid, 2023 Validated on sample
815 million total, 2023 Asserted, not shown
Central repository breached Not established

What changed. UIDAI Circular No. 1 of 2018, dated 10 January 2018, introduced three mechanisms: the Virtual ID, a revocable temporary sixteen-digit number that a person can generate and share instead of their Aadhaar number; the UID Token, a per-agency pseudonymous identifier so that two agencies holding tokens for the same person cannot correlate them; and Limited KYC, restricting many agencies to receiving a token and the minimum attributes rather than the number itself. Implementation was set for 1 June 2018 and extended by a further circular dated 5 June 2018 to 1 July 2018.

Look at what those three things are. The Virtual ID is revocability retrofitted onto an identifier designed to be permanent. The UID Token is sector-specific pseudonymization, the same idea as a directed identifier in a federation protocol. Limited KYC is data minimization. All three are textbook privacy engineering, and all three arrived after years of downstream leakage had made the case unanswerable. The lesson generalizes far beyond India: if you issue a permanent identifier and let every relying party store it, you will eventually have to build a revocable, sector-specific layer on top, and it is far cheaper to build it first.

The root causes, counted#

Here is the worked example promised earlier, carried all the way through. Eight causes, nine incidents, scored from the public reports described above.

The causes, with the shorthand used in the table:

  1. C1 Bearer credential. A password, one-time code, cookie or token that grants access to whoever holds it, with no binding to a specific device or key.
  2. C2 Human as authenticator. A help desk, support engineer or operator whose judgement is the actual authentication decision.
  3. C3 Third party inside the boundary. A contractor, outsourced desk, supplier’s software or downstream portal operating within the trust perimeter.
  4. C4 Known flaw unclosed. A published vulnerability with a published fix, unpatched because it was not found or not tracked.
  5. C5 Long blindness. Substantial time between intrusion and detection attributable to missing or broken telemetry.
  6. C6 Excess standing privilege. One account or system able to reach far more than its function requires; no segmentation.
  7. C7 Key beside the lock. Encrypted material and its key, or credentials and the systems they open, stolen in one bundle.
  8. C8 Identifier used as a secret. A permanent label -- national number, date of birth, address history -- treated as proof of identity.
Cause Cases hit Count of 9
C1 Bearer credential OPM, LP, Ok22, Ok23, MGM, CH 6
C2 Human as authenticator Ok22, MGM 2
C3 Third party inside all but EFX and Ok23 7
C4 Known flaw unclosed OPM, EFX, LP 3
C5 Long blindness all nine 9
C6 Excess privilege all but Aadhaar 8
C7 Key beside lock EFX, SW, LP, Ok23 4
C8 Identifier as secret OPM, EFX, MGM, Aad, CH 5

The abbreviations are OPM 2015, EFX Equifax 2017, SW SolarWinds 2020, LP LastPass 2022, Ok22 Okta January 2022, Ok23 Okta October 2023, MGM the MGM and Caesars pair of 2023, Aad the Aadhaar downstream portal exposure documented in 2017, and CH Change Healthcare 2024 -- included because its root cause is the cleanest in the set: entry through a remote access service using valid credentials with no second factor, an actor inside the network from 12 to 20 February 2024, detection on 21 February 2024, and a final total reported to the United States health regulator of 192.7 million individuals.

Tally arithmetic
----------------
Cells in the matrix   = 8 causes x 9 cases = 72
Cells marked present  = 6+2+7+3+9+8+4+5    = 44
Fill rate             = 44 / 72            = 0.611

Causes present in 6 or more of the 9 cases:
   C5 (9), C6 (8), C3 (7), C1 (6)
   -> these four account for 30 of the 44 marks
   -> 30 / 44 = 0.682 of all marks

Causes present in 3 or fewer:
   C2 (2), C4 (3)
   -> 5 of 44 marks = 0.114

Read the arithmetic honestly. Four causes carry 68 percent of the marks, and they are: you could not see, you gave out too much access, you let somebody else stand inside your fence, and your credentials could be carried away by whoever picked them up. Those four are also, conveniently, the four that a competent identity architecture addresses directly: telemetry, least privilege, third-party isolation and phishing-resistant device-bound credentials.

Note what is low. C4, the known unpatched flaw, appears in only three of nine, which contradicts the popular story that breaches are mostly about patching. C2, the human as authenticator, appears in only two, but that is not a licence to ignore it: it is the fastest-growing category, it accounted for the most operationally disruptive incidents of 2023, and its low count here is partly an artefact of choosing nine famous cases spread over a decade.

The caveat, repeated: this is my scoring of public reports using categories I chose. It is analysis, not measurement. C5 scoring nine out of nine is a warning sign of the survivorship problem described earlier, since an intrusion detected in minutes rarely becomes a case study. Another analyst would move two or three cells. None would move the top four.

What each incident changed, with dates#

The following table is the answer to the chapter’s thesis. Each row is a control that exists because of something specific.

Incident Change that followed Date
OPM 2015 Federal PIV enforcement push Jun 2015
OPM 2015 Zero trust urged by Congress 7 Sep 2016
Equifax 2017 Free credit freezes in US 21 Sep 2018
Equifax 2017 PLA indictment, 9 counts 10 Feb 2020
SolarWinds CISA Emergency Directive 21-01 13 Dec 2020
SolarWinds Golden SAML detection guidance 8 Jan 2021
SolarWinds Executive Order 14028, SBOM 12 May 2021
Federal-wide M-22-09 phishing-resistant MFA 26 Jan 2022
Okta 2022 Subprocessor access review 2022
Okta Aug 2023 Cross-tenant impersonation 31 Aug 2023
Casinos 2023 SEC Item 1.05 8-K compliance 18 Dec 2023
Casinos 2023 Scattered Spider advisory 16 Nov 2023
Okta Oct 2023 Admin session token binding Nov 2023
LastPass 2022 PBKDF2 default to 600,000 2023
Aadhaar leaks Virtual ID, UID Token, KYC 10 Jan 2018
Sector-wide NIST SP 800-63-4 published 31 Jul 2025

Two of those deserve elaboration.

The final row is the most consequential for anyone building systems today. The NIST Digital Identity Guidelines were revised as SP 800-63-4, published on 31 July 2025, comprising SP 800-63A-4 on identity proofing, SP 800-63B-4 on authentication, and SP 800-63C-4 on federation. The whole arc of that document family, from the SP 800-63-3 revision of June 2017 onwards, is a response to the class of failures in this chapter: away from knowledge-based verification, which Equifax rendered indefensible; away from SMS as a second factor, which SIM swapping rendered indefensible; and toward phishing-resistant, device-bound authenticators and explicit treatment of syncable credentials.

The phishing-resistance row is the one to test your understanding on. In August 2022, a single campaign that Group-IB named 0ktapus compromised 9,931 accounts across more than 130 organizations by sending employees text messages linking to convincing fake login pages. Twilio disclosed its compromise on 8 August 2022. Cloudflare published its own account on 9 August 2022: three of its employees fell for the message and entered their credentials, and the attack still failed, because every Cloudflare employee is issued a FIDO2-compliant hardware security key and that key will not produce a signature for a website whose origin does not match. The employees did everything wrong. The credential refused to cooperate. That is the entire argument for origin-bound, hardware-backed authentication, demonstrated in a single week against a single adversary with two organizations as the control group.

What you would need to have seen it#

For each case, the detection that was missing is specific and cheap to name. This section is the practical residue of the chapter.

For OPM, the missing detection was egress analysis and privileged account behaviour: a contractor credential used from an unusual source, at an unusual hour, touching systems that role did not require. Also missing was the discipline of assuming multiple simultaneous adversaries. The Big Bang was planned against a single known intruder, which is a plan built on an assumption nobody had tested.

For Equifax, the missing detection was an asset inventory that could answer “which of our internet-facing hosts run Apache Struts”, and a monitoring pipeline whose own health was monitored. Any control that can degrade without raising an alarm will eventually degrade without raising an alarm.

  # The check that would have caught the Equifax
  # inspection gap. Any certificate on a security
  # control, not just a public web server.
for host in $(cat security-appliances.txt); do
  end=$(echo | openssl s_client -connect "$host:443" \
        2>/dev/null | openssl x509 -noout -enddate)
  echo "$host $end"
done

  # The health signal that matters more than the
  # certificate: is the device still producing
  # output? inspected_flows_per_hour must be
  # nonzero and near its 30-day baseline.

For Okta in 2022, the missing control was constraining what an outsourced support engineer can do to a customer tenant without that customer’s approval. For Okta in 2023, it was two things: server-side scrubbing of uploaded attachments so that session tokens never rest in a support system, and session binding so that a stolen token is useless from a different network. Both now exist; neither was standard beforehand.

For LastPass, the missing controls were device separation for staff with access to production key material, and a migration programme that moved every existing customer to current key derivation parameters rather than only new ones. The second is the harder organizational lesson: security parameters that apply only to new accounts leave your longest-standing customers with the weakest protection.

For SolarWinds, the missing detection is in AA21-008A and is worth internalizing: authentications at a service provider with no corresponding authentication event at the identity provider. If your cloud audit log shows a sign-in that your domain controller never saw, either your logging is broken or somebody is forging tokens, and both need answering today.

For the casino attacks, the missing control was procedural: no telephone-based reset of authenticators for privileged accounts, identity verification at recovery at least as strong as at enrolment, and out-of-band notification to the real user on every authenticator change with a delay long enough to be objected to.

For Aadhaar’s downstream exposure, the missing control was governance: a rule that a national identifier may not appear in any transparency, audit or beneficiary report, enforced by scanning published datasets for identifier patterns. That is a search job, not a cryptography job.

How to read the next one#

There will be another. Read it with six fixed questions and you will extract more in twenty minutes than most commentary manages in a week.

What exactly was taken, field by field, and which of those fields can be reissued: passwords yes, session tokens yes, card numbers yes, national identifiers rarely, biometrics never. How long was the attacker present, and who found them; if the answer to the second is a customer, a journalist or a researcher, the telemetry lesson outranks every other lesson in the report. What was the initial access, and would a device-bound credential have stopped it; for six of the nine cases here, the answer is yes or probably. What did the attacker reach that they should not have been able to reach from where they landed, and what would segmentation have cost. Which numbers are measured, which are estimated and which are asserted by the attacker; split the report into those three piles before you quote anything.

And last, what changed afterwards, and is it a default or an option. A control that exists as an option in a settings page protects the customers who read settings pages. A control that becomes the default protects everybody. The most valuable outcome of any breach is not a new feature. It is a changed default.

58.98 Common wrong ideas#

Wrong: The OPM breach was one intrusion that went undetected for a year. Right: There were two distinct adversaries, labelled X1 and X2; X1 was detected in March 2014 and expelled in the Big Bang remediation of 27 May 2014, while X2 had entered on 7 May 2014 using a contractor’s credentials, was not part of that plan, and remained until 15 April 2015.

Wrong: Equifax was breached because it failed to apply a patch. Right: Failure to patch CVE-2017-5638 opened the door, but the 76-day extraction, the reach from three databases to fifty-one and the 9,000 queries were made possible by plain-text credentials stored on the network, absent segmentation, and a traffic inspection device blinded by a certificate that GAO says had expired about ten months earlier.

Wrong: The Okta 2023 incident exposed 134 customers. Right: 134 customers had support files accessed and five suffered session hijacking, but on 29 November 2023 Okta further disclosed that a report holding the names and email addresses of all customer support system users had been downloaded on 28 September 2023, so the phishing exposure covered every support system user.

Wrong: LastPass vaults were encrypted, so customers were safe. Right: Website URLs and account metadata were not encrypted at all, which alone gives an attacker a targeting list; vault contents were only as strong as each customer’s master password and iteration count; and for the stolen multi-factor and federation database the decryption key was taken with the ciphertext, so encryption protected that artefact not at all.

Wrong: SolarWinds was a code signing failure. Right: Code signing worked as specified and verified a genuine publisher; the compromise was of the build process before signing, and the identity damage came from stealing Active Directory Federation Services token-signing keys and forging SAML assertions, which produces service provider logins with no corresponding domain controller authentication events.

Wrong: The casino attacks of 2023 were sophisticated hacking. Right: The documented entry technique, per joint advisory AA23-320A of 16 November 2023, was telephoning or messaging IT and help desk staff while posing as an employee, alongside repeated multi-factor prompts, SIM swapping and look-alike single sign-on domains; the sophistication was social and operational, not technical.

Wrong: The Aadhaar database of over a billion people has been breached. Right: No compromise of the central repository has been established; what is documented is that 130 to 135 million Aadhaar numbers were published by four government portals themselves, per the Centre for Internet and Society report of 1 May 2017, and that of the 815 million records advertised in October 2023 only about 400,000 sample records were released and validated, with the source never disclosed.

Wrong: These breaches all had different causes, so there is no general lesson. Right: Scoring nine major incidents against eight root causes fills 44 of 72 cells, and four causes -- undetected presence, excessive standing privilege, third parties inside the trust boundary and bearer credentials -- account for 30 of those 44 marks, so a small number of architectural decisions would have blunted most of them.

Wrong: Multi-factor authentication would have prevented these attacks. Right: Several victims had it, and it was defeated by resetting factors through a help desk, by prompt fatigue, by SIM swapping or by stealing a post-authentication session cookie; what the evidence supports is origin-bound, hardware-backed authentication, as when three Cloudflare employees entered credentials into a phishing page in August 2022 and the attack still failed because FIDO2 keys refuse to sign for the wrong origin.

Wrong: Regulation after a breach is symbolic. Right: Some of it is measurable and immediate: free nationwide credit freezes took effect in the United States on 21 September 2018, CISA Emergency Directive 21-01 of 13 December 2020 gave federal agencies less than a day to disconnect affected systems, and SEC Form 8-K Item 1.05 has required disclosure of material cybersecurity incidents since 18 December 2023.

58.99 Chapter summary in 20 lines#

  1. Every control described in this book has a date attached to it, because a specific failure to specific people is what ended the argument for it.
  2. The 2015 OPM disclosures covered 21.5 million background investigation records, including 19.7 million applicants and 1.8 million spouses and cohabitants who had applied for nothing.
  3. On 23 September 2015 OPM revised the number of stolen fingerprint sets from 1.1 million to 5.6 million, and fingerprints are the one stolen credential for which no reissue procedure exists.
  4. The OPM remediation known as the Big Bang, executed on 27 May 2014, expelled the first adversary while a second that had entered on 7 May 2014 stayed inside until 15 April 2015.
  5. The House Oversight Committee report of 7 September 2016 called the breach preventable and recommended reprioritizing federal security toward zero trust, five and a half years before the federal zero trust memorandum.
  6. Equifax was entered through CVE-2017-5638 in Apache Struts 2, publicly identified by US-CERT on 8 March 2017 and scanned for against Equifax on 10 March 2017.
  7. Attackers reached 51 databases, ran approximately 9,000 queries and removed data over 76 days undetected, because a traffic inspection device was blind due to an expired digital certificate.
  8. GAO-18-559 puts the Equifax total at at least 145.5 million individuals and the settlement of 22 July 2019 at approximately 147 million, with Equifax paying at least $575 million and potentially up to $700 million.
  9. Free nationwide credit freezes took effect in the United States on 21 September 2018, as direct a line from a breach to a statutory right as this chapter contains.
  10. Okta’s January 2022 incident gave an attacker 25 consecutive minutes of control over an outsourced support engineer’s workstation, with a maximum potential impact of 366 customers and an actual impact of two.
  11. Okta’s October 2023 incident began with a service account credential saved into an employee’s personal Google profile and ended with session tokens harvested from customer-uploaded HAR files.
  12. BeyondTrust records an attacker using a session cookie from an uploaded HAR file within thirty minutes, being blocked at the console by device policy, and pivoting to the API to create a persistence account.
  13. The LastPass theft left website URLs and account metadata unencrypted, protected vault contents only in proportion to each master password, and protected not at all the artefact whose key was stolen alongside it.
  14. LastPass moved to 600,000 PBKDF2 iterations, which multiplies an attacker’s guessing time by about six, while a four-word passphrase instead of a word plus two digits multiplies it by billions.
  15. SUNBURST was carried in Orion Platform 2019.4 HF 5, 2020.2 and 2020.2 HF 1, reached approximately 18,000 of SolarWinds’ roughly 300,000 customers, and was followed by exploitation of fewer than a hundred.
  16. The identity consequence of SolarWinds was golden SAML: stealing an ADFS token-signing key and forging assertions, detectable as service provider logins with no matching domain controller authentication event.
  17. Caesars disclosed on 14 September 2023 that social engineering of an outsourced IT support vendor led to theft of its loyalty database, and MGM’s 8-K of 5 October 2023 estimated a $100 million impact.
  18. In the Aadhaar case, 130 to 135 million numbers published by four government portals in 2017 is documented, while the 815 million records advertised in October 2023 rest on validated samples of about 400,000 from an undisclosed source.
  19. Scoring nine incidents against eight root causes fills 44 of 72 cells, with undetected presence, excess standing privilege, third parties inside the boundary and bearer credentials taking 30 of the marks.
  20. The most valuable outcome of any breach is not a new product feature but a changed default, because an option protects the people who read settings pages and a default protects everybody.

Chapter sources: US House Committee on Oversight and Government Reform majority staff report, “The OPM Data Breach: How the Government Jeopardized Our National Security for More than a Generation”, 7 September 2016; OPM statements of 4 June, 9 July and 23 September 2015 giving 4.2 million personnel records, 21.5 million background investigation records made up of 19.7 million applicants and 1.8 million non-applicants, and the revision of stolen fingerprint sets from 1.1 million to 5.6 million. Government Accountability Office report GAO-18-559, “Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach”, August 2018, for at least 145.5 million individuals, 51 databases, approximately 9,000 queries, the 76-day extraction window, approximately 209,000 credit card numbers and 182,000 dispute documents, and a digital certificate expired about ten months before the breach; Senate Permanent Subcommittee on Investigations staff report “How Equifax Neglected Cybersecurity and Suffered a Devastating Data Breach”, March 2019, for the certificate expired since November 2016 and the 78-day detection delay; CVE-2017-5638 in the Apache Struts 2 Jakarta Multipart parser; FTC press release of 22 July 2019 on the at least $575 million global settlement affecting approximately 147 million people; Department of Justice announcement of 10 February 2020 on the nine-count indictment of four members of the People’s Liberation Army 54th Research Institute; FTC press release of 21 September 2018 on free credit freezes under the Economic Growth, Regulatory Relief, and Consumer Protection Act. Okta security posts “Okta’s Investigation of the January 2022 Compromise” and “Okta Concludes its Investigation Into the January 2022 Compromise” for the 20 to 21 January 2022 timeline, the 366 customer maximum potential impact and the 25 consecutive minutes of workstation control; Okta advisory “Cross-Tenant Impersonation: Prevention and Detection”, 31 August 2023; Okta post “Unauthorized Access to Okta’s Support Case Management System: Root Cause and Remediation”, 3 November 2023, for the 28 September to 17 October 2023 window, the 134 customers, the five session hijackings and the Chrome personal profile root cause; Okta’s disclosure of 29 November 2023 that a report of all support system users was downloaded on 28 September 2023, with 99.6 percent of entries holding only name and email; BeyondTrust’s published account of the same incident. LastPass “Notice of Recent Security Incident” and “Security Incident Update and Recommended Actions” of 1 March 2023, for the two incidents, the senior DevOps engineer as one of four with corporate vault access, the vulnerable third-party media software package, the cessation of activity on 26 October 2022, the unencrypted website URLs, the AES-256 encrypted fields, the twelve-character minimum and 100,100 PBKDF2 iterations since 2018, and the stolen decryption key for the multi-factor and federation database backup; the OWASP Password Storage Cheat Sheet PBKDF2 figures of 310,000 and later 600,000 iterations. CISA Emergency Directive 21-01, 13 December 2020, with supplemental guidance of 18 and 30 December 2020, 6 January 2021 and supplemental direction of 22 April 2021; CISA advisory AA20-352A for Orion Platform 2019.4 HF 5, 2020.2 and 2020.2 HF 1 at file versions 2019.4.5200.9083 and 2020.2.5300.12432; CISA advisory AA21-008A, “Detecting Post-Compromise Threat Activity in Microsoft Cloud Environments”, 8 January 2021, updated 15 April 2021 with attribution to the Russian Foreign Intelligence Service, for golden SAML detection using event IDs 4769, 1200, 1202, 307 and 510 and unified audit log value 16457; SolarWinds SEC filing figure of approximately 18,000 of roughly 300,000 customers, GAO-22-104746 for fewer than 100 customers actually compromised, and the White House briefing of 17 February 2021 citing nine federal agencies and about 100 private sector companies; SEC Litigation Release No. 26423 of 20 November 2025. Caesars Entertainment Form 8-K of 14 September 2023 and MGM Resorts International Form 8-K of 5 October 2023; joint advisory AA23-320A on Scattered Spider, 16 November 2023, updated 21 November 2023; SEC press release 2023-139 of 26 July 2023 adopting the cybersecurity disclosure rules with Form 8-K Item 1.05 compliance from 18 December 2023. Centre for Internet and Society report by Amber Sinha and Srinivas Kodali, “Information Security Practices of Aadhaar (or lack thereof)”, 1 May 2017, with the authors’ clarification giving portal figures of 109,760,343, 6,395,317 and 20,560,896; The Tribune report of 4 January 2018 by Rachna Khaira; UIDAI Circular No. 1 of 2018 of 10 January 2018 on Virtual ID, UID Token and Limited KYC, and Circular No. 06 of 2018 of 5 June 2018 extending implementation to 1 July 2018; Resecurity report of 15 October 2023 on the 815 million record listing and the roughly 400,000 sample records released between 9 and 13 October 2023. HHS Office for Civil Rights breach reporting for Change Healthcare at 192.7 million individuals; Cloudflare’s incident post of 9 August 2022 and Group-IB’s 0ktapus research on 9,931 accounts across more than 130 organizations; OMB Memorandum M-22-09 of 26 January 2022; Executive Order 14028 of 12 May 2021; NIST SP 800-63-4, “Digital Identity Guidelines”, 31 July 2025, comprising SP 800-63A-4, SP 800-63B-4 and SP 800-63C-4.