---
title: Okta SSO Accounts Targeted in Vishing-Based Data Theft Attacks
metaTitle: "Vishing Attacks Target Okta SSO Accounts"
description: "Threat actors, armed with versatile vishing kits, are targeting specific employees to steal SSO credentials and TOTP codes, and, in turn, enterprise data."
slug: vishing-attacks-target-okta-sso-accounts
date: "2026-01-22T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/slx/images/vishing-attacks-target-okta-sso-accounts.webp"
  alt: A finger pressing an important-looking biometric scanner.
sourcePublisher:
  name: Bleeping Computer
  url: "https://www.bleepingcomputer.com/"
sourceArticle:
  url: "https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-in-vishing-based-data-theft-attacks/"
tags: ["Vishing", "Spoofing", "Tech Support Scam"]
status: published
---

Okta is warning about custom phishing kits built specifically for voice-based social engineering (vishing) attacks. BleepingComputer has learned that these kits are being used in active attacks to steal Okta SSO credentials for data theft.

In a new report released today by Okta, researchers explain that the phishing kits are sold as part of an “as a service” model and are actively being used by multiple hacking groups to target identity providers, including Google, Microsoft, and Okta, and cryptocurrency platforms.

Unlike typical static phishing pages, these adversary-in-the-middle platforms are designed for live interaction via voice calls, allowing attackers to change content and display dialogs in real time as a call progresses...
