On Friday 20 October 2023, Okta — the identity provider through which a very large share of the corporate world logs into everything else — disclosed that an attacker had used a stolen credential to enter its customer support case management system and view files uploaded by customers. The root cause, in Okta's own later report, was almost painfully ordinary: a service account's username and password had been saved into an employee's personal Google account after that employee signed into Chrome on an Okta-managed laptop.

The prize was HAR files. When a customer has a problem, support engineers often ask for an HTTP Archive — a browser session recording that captures exactly what happened. It is an excellent diagnostic tool and, it turns out, an excellent theft target, because some HAR files contain live session tokens. A stolen session token does not need a password or a second factor; it is proof that authentication already happened. The attacker had spent from 28 September to 17 October inside the system — roughly twenty days — before disclosure.

The victims noticed before Okta told them. 1Password flagged suspicious activity to Okta around 29 September, which Okta initially treated as a possible problem on 1Password's side. BeyondTrust saw attacker activity within about thirty minutes of uploading a HAR file on 2 October, escalated immediately, and says Okta did not confirm the breach to it until 19 October — roughly two and a half weeks later. Cloudflare detected its own intrusion on 18 October. Okta stated that files belonging to 134 customers were accessed and session hijacking was attempted against five.

The market's verdict was immediate: Okta's shares fell about 11% on the day and kept sliding, erasing more than $2 billion in value within days. And the scope grew after the month closed — on 29 November, Okta revised its assessment to say the attacker had also downloaded a report containing the names and email addresses of all users of its customer support system, drawn from a base of more than 18,400 customers.

Also that month · Implants at scale

A CVSS 10.0 and tens of thousands of routers

On 16 October, Cisco disclosed CVE-2023-20198 — an unauthenticated privilege-escalation flaw in the IOS XE Web UI, rated a maximum-severity 10.0, and already being exploited. Attackers chained it with a second bug to write persistent implants onto routers and switches, and internet-wide scans counted implanted devices in the tens of thousands. Then, over the weekend of 21–22 October, the counts appeared to collapse to a few hundred. It was not cleanup. Fox-IT showed on 23 October that the attackers had simply modified the implant to stay silent unless a scanner supplied a correct authorization header; a corrected fingerprint still found 37,890 compromised devices. The attackers had made themselves invisible to the world's counting, and for two days the industry believed the good news.

Also that month · Fourteen thousand doors, millions of rooms

23andMe and the relatives who never logged in

From 1 October, posts advertising 23andMe DNA Relatives profile data appeared on BreachForums. The company later attributed the intrusion to credential stuffing — reused passwords from other breaches — rather than any compromise of its own systems. Roughly 14,000 accounts were directly accessed. Because the opt-in DNA Relatives and Family Tree features are designed to connect users to their genetic kin, the attacker could then pivot outward to profile data on about 6.9 million people, most of whom had done nothing wrong and had no account to protect. That final figure emerged only in a December filing; October was the month the sale posts appeared.

India desk · October 2023

815 million records, priced at $80,000

On 9 October 2023, an actor using the handle "pwn0001" opened a BreachForums thread offering what they described as 815 million "Indian Citizen Aadhaar & Passport" records, asking $80,000 for the full dataset. The listing was surfaced by researchers at Resecurity, whose report drove mainstream Indian coverage at the end of the month. Sample records reportedly contained name, age, gender, address, PIN code, full unmasked Aadhaar number, passport number where applicable, and phone number.

Researchers and Indian media attributed the likely source to Indian Council of Medical Research databases used for COVID-19 RT-PCR testing — an attribution never officially confirmed. Two caveats belong in the record permanently: 815 million is the seller's claim, never independently verified end to end, and UIDAI has consistently maintained that Aadhaar's central repository itself was not breached, pointing instead to downstream databases that store Aadhaar numbers. What is confirmed is the response: CERT-In investigated, the CBI took up the case after ICMR filed a complaint, and Delhi Police arrested four people in December. Whatever the true number, October 2023 was the month India's identity infrastructure became a headline commodity — and it landed two months after Parliament had passed a data protection act that was not yet in force.

⏳ Time capsule — October 2023

  • The ICC Men's Cricket World Cup opened in Ahmedabad on 5 October, with India hosting all matches across ten venues.
  • Microsoft completed its $68.7 billion acquisition of Activision Blizzard on 13 October, the largest deal in video-game history.
  • "Taylor Swift: The Eras Tour" opened in cinemas on 13 October and became the highest-grossing concert film ever.
  • An annular "ring of fire" eclipse crossed the Americas on 14 October.
Where it stands today — 2026

The support channel is production

Okta's HAR-file breach permanently changed how the industry treats support tooling: sanitising diagnostic uploads, binding sessions to devices, and shortening token lifetimes all became standard, and "the support system is a production system" entered the vocabulary. Its deeper lesson — that identity providers are the highest-value target in any environment because they sit above everything else — runs straight through this archive to the Salesloft token theft of 2025 and the OAuth campaigns of 2026. The Cisco implant episode remains the standard warning about measuring security by what scanners can see. And India's 815 million records marked the beginning of a national argument about identity data that the DPDP framework is, three years later, still working through.