Every claim in this report traces back to one of 40 evidence records below. Each was captured passively during recon, hashed at capture for chain-of-custody, and graded per the Admiralty Scale (NATO STANAG 2511). Click any ev_xxx chip elsewhere in the report to jump straight to its source record.
Okta, Inc. is an American identity and access management company based in San Francisco. It provides cloud software that helps companies manage and secure user authentication into applications, and for developers to build identity controls into applications, websites, web services, and devices. It was founded in 2009 and had its initial public offering in 2017.
Microsoft Entra ID is a cloud-based identity and access management (IAM) solution. It is a directory and identity management service that operates in the cloud and offers authentication and authorization services to various Microsoft services, such as Microsoft 365, Dynamics 365, Microsoft Azure, and third-party services.
Ping Identity Corporation is an American software company established in 2002 by Andre Durand and Bryan Field-Elliot. It is headquartered in Denver. It was a publicly traded company until getting acquired by Thoma Bravo and taken private in October 2022.
SourceWikipedia — Identity and access management·Captured
Identity and access management or Identity management (IdM) is a framework of policies and technologies to ensure that the right users have the appropriate access to technology resources. IAM systems fall under the overarching umbrellas of IT security and data management.
JumpCloud is an American enterprise software company headquartered in Louisville, Colorado. The company was formally launched in 2013. JumpCloud offers a cloud-based directory platform that centralizes identity, access, and device management for both human and non-human identities.
SourceGartner — Magic Quadrant for Access Management·Captured
Gartner Magic Quadrant for Access Management. A graphical competitive positioning of Leaders, Visionaries, Niche Players and Challengers (December 2024 edition).
SourceOkta Security — Okta's Investigation of the January 2022 Compromise·Captured
On January 20, 2022, the Okta Security team was alerted that a new factor was added to a Sitel customer support engineer's Okta account. The threat actor (Lapsus$) had access to a Sitel support engineer's laptop from January 16-21, 2022.
SourceOkta Security — Unauthorized Access to Okta's Support Case Management System·Captured
A threat actor gained unauthorized access to files inside Okta's customer support system associated with 134 Okta customers, or less than 1% of Okta customers. Subsequent disclosure (Nov 29 2023) confirmed names and email addresses of all Okta customer-support system users were also exfiltrated.
Scattered Spider threat actors use social engineering to convince IT helpdesk personnel to reset passwords and/or MFA tokens. Notable targets included MGM Resorts and Caesars Entertainment in September 2023.
SourceThoma Bravo — How Ping Identity Mastered Identity Security for Global Enterprises·Captured
Thoma Bravo acquired Ping Identity in October 2022 for $2.8 billion in a take-private transaction. Subsequently, in August 2023, Ping Identity acquired ForgeRock, creating the market leader for access management solutions.
SourceThoma Bravo — SailPoint to be Acquired by Thoma Bravo for $6.9 Billion·Captured
Thoma Bravo will acquire SailPoint for $65.25 per share in an all-cash transaction that values SailPoint at an equity value of approximately $6.9 billion. Closing in the second half of 2022.
SourceThoma Bravo — Completes Acquisition of ForgeRock; Combines ForgeRock into Ping Identity·Captured
Software investor Thoma Bravo acquired ForgeRock in an all-cash transaction valued at approximately $2.3 billion and combined ForgeRock into its portfolio company Ping Identity (August 23, 2023).
SourceCyberArk — Completes Acquisition of Machine Identity Management Leader Venafi·Captured
CyberArk intends to acquire Venafi for an enterprise value of approximately $1.54 billion in a combination of cash and CyberArk shares. Deal closed October 1, 2024 per CyberArk Q4 2024 investor materials.
SourcePalo Alto Networks — Completes Acquisition of CyberArk to Secure the AI Era·Captured
Announced July 30, 2025 at approximately $25 billion. Completed February 11, 2026. The addition of the CyberArk Identity Security Platform enables Palo Alto Networks to secure every identity across the enterprise — human, machine, and AI.
SourceMicrosoft Security Blog — Analysis of Storm-0558 techniques for unauthorized email access·Captured
Beginning May 15, 2023, Storm-0558 used forged authentication tokens to access user email from approximately 25 organizations, including government agencies. State Department detected the activity via enhanced (G5) logging.
SourceOkta — What Are Non-Human Identities and How to Secure Them·Captured
Non-human identities (NHIs) are the invisible drivers of modern infrastructure. Every human and machine identity should be treated as untrusted by default. Lifecycle gaps increase risk.
SourceMicrosoft Identity Blog — Azure AD is being renamed to Microsoft Entra ID·Captured
Azure Active Directory (Azure AD) is being renamed to Microsoft Entra ID as part of our commitment to simplify secure access experiences. Announced July 11, 2023.
SourceReuters — Thoma Bravo-backed SailPoint set for US market comeback·Captured
Thoma Bravo-backed SailPoint raised $1.38 billion in an upsized IPO and began trading on Nasdaq under ticker SAIL on February 13, 2025 at a $12.8 billion market value.
SourceCisco Newsroom — Cisco Completes Acquisition of Duo Security·Captured
Cisco acquired Duo Security for $2.35 billion in cash and assumed equity awards for 100% of Duo's outstanding shares, warrants and equity. Closed October 1, 2018.
SourceAuth0 / Okta — Okta Completes Acquisition of Auth0·Captured
Okta, Inc. today (May 3, 2021) announced the successful completion of its acquisition of Auth0. All-stock transaction valued at approximately $6.5 billion at announcement.
The FIDO Alliance is an open industry association launched in February 2013 whose stated mission is to develop and promote authentication standards that 'help reduce the world's over-reliance on passwords.'
SourceNIST CSRC — SP 800-207, Zero Trust Architecture·Captured
NIST Special Publication 800-207, Zero Trust Architecture, Date Published: August 2020. The U.S. federal-government anchor publication for ZTA reference architectures.
OpenID is an open standard and decentralized authentication protocol promoted by the non-profit OpenID Foundation. OpenID Connect (built on OAuth 2.0) was finalized in 2014.
Security Assertion Markup Language is an open standard for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider.
OAuth is an open standard for access delegation, commonly used as a way for internet users to grant websites or applications access to their information on other websites but without giving them the passwords.
Web Authentication (WebAuthn) is a web standard published by the World Wide Web Consortium (W3C). It defines an API that websites use to authenticate with WebAuthn credentials (passkeys) and outlines what WebAuthn authenticators should do.
SourceFIDO Alliance — Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard·Captured
Apple, Google and Microsoft today (May 5, 2022) announced plans to expand support for a common passwordless sign-in standard created by the FIDO Alliance and the World Wide Web Consortium.
Active Directory (AD) is a directory service developed by Microsoft for Windows domain networks. Originally, only centralized domain management used Active Directory; it has since become an umbrella for various directory-based identity-related services.
Privileged Access Management (PAM) is a type of identity management and branch of cybersecurity that focuses on the control, monitoring, and protection of privileged accounts within an organization.
SourceWikipedia — Zero trust architecture·Captured
Zero trust architecture (ZTA) is a design and implementation strategy of IT systems. The principle is that users and devices should not be trusted by default, even if they are connected to a privileged network such as a corporate LAN.
SourceCISA — Known Exploited Vulnerabilities Catalog (Microsoft Active Directory)·Captured
CVE-2022-26923, CVE-2021-42287, CVE-2021-42278 — three Microsoft Active Directory Domain Services privilege-escalation vulnerabilities catalogued in KEV with known ransomware-campaign use for the two 2021 CVEs.
SourceMordor Intelligence — IAM Security Services Market·Captured
Consolidation surged in 2025 when Palo Alto Networks agreed to acquire CyberArk for USD 25 billion, merging privileged-access oversight with broader cybersecurity offerings.
SourceVerizon — 2024 Data Breach Investigations Report·Captured
Phishing is the most common credential-related attack. Stolen credentials remain among the most prevalent initial-access vectors in confirmed data breaches.
Multi-factor authentication (MFA), also known as two-factor authentication (2FA), is an electronic authentication method in which a user is granted access only after successfully presenting two or more distinct types of evidence.
Single sign-on (SSO) is an authentication scheme that allows a user to log in with a single ID to any of several related, yet independent, software systems.