---
title: Vishing Attacks on Okta Identity Systems on the Rise
metaTitle: Vishing Attacks on Okta ID Systems Rise
description: Vishing attacks are targeting IT help desks directly to bypass Okta MFA, allowing attackers to gain organization-wide access to SaaS platforms.
slug: vishing-attacks-on-okta-identity-systems
date: "2026-04-15T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/slx/images/vishing-attacks-on-okta-id-systems.webp"
  alt: "A pixel art key."
sourcePublisher:
  name: SC Media
  url: "https://www.scworld.com/"
sourceArticle:
  url: "https://www.scworld.com/news/vishing-attacks-on-okta-identity-systems-on-the-rise"
tags: [Vishing, Tech Support Scam]
status: published
---

Vishing attacks on Okta identity systems have increased in which attackers simply call the victim or an IT help desk and convince them to weaken or reset multi-factor authentication (MFA).

In an April 13 blog post, LevelBlue researchers said once Okta is compromised via vishing, the attackers gain access to an enterprise’s SaaS systems via single sign-on (SSO), which leads to the exfiltration of SharePoint, OneDrive, Salesforce, and Google Workspace data.

The LevelBlue researchers explained that as part of the attack, the threat actors aim to get the victim or help desk to reset MFA, enroll a new authenticator device, provide one-time passcodes, disclose passwords, or reset Okta credentials...
