---
title: Hackers Exploit Vishing To Bypass MFA at Okta
metaTitle: "Hackers Exploit Vishing To Bypass MFA at Okta"
description: "Highly coordinated vishing attacks are steering employees around tech-based guardrails, collecting full sets of login credentials, including MFA codes."
slug: hackers-vishing-to-bypass-mfa
date: "2026-02-02T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/slx/images/hackers-vishing-to-bypass-okta-mfa.webp"
  alt: A person peering through a small hole.
sourcePublisher:
  name: Techinformed
  url: "https://techinformed.com/"
sourceArticle:
  url: "https://techinformed.com/hackers-exploit-vishing-to-bypass-mfa-at-okta/"
tags: ["Vishing", "Spoofing", "Tech Support Scam", "Credential Harvesting"]
status: published
---

Hackers are using voice-based social engineering to bypass multi-factor authentication (MFA) protections and steal Okta single sign-on (SSO) credentials, according to recent reporting and a new threat advisory from the identity provider.

Recently, BleepingComputer reported that attackers posing as IT support staff used vishing calls and real-time adversary-in-the-middle infrastructure to capture Okta SSO credentials and one-time passwords during live login sessions, activity that Okta later said it had “detected and dissected” through its threat intelligence investigations.

Okta, an enterprise identity and access management provider, said the activity involved custom phishing kits designed to support live caller-led attacks, where a caller can control what a victim sees in a browser while walking them through login prompts...
