{"success":true,"data":{"id":"okta-fastpass-recovery-phish","label":"Fake Okta FastPass re-enrollment or MFA factor reset targeting SSO access from non-okta.com sender","description":"Fake Okta FastPass re-enrollment or MFA authentication factor reset email directing victims to re-enroll their Okta Verify app from a non-okta.com sender. Okta is the dominant enterprise SSO/identity platform with 19,000+ enterprise customers — a single phished Okta credential grants access to dozens of downstream SaaS applications. Attackers send fake \"Your Okta FastPass authenticator needs to be re-enrolled within 24 hours to maintain access\" or \"Your Okta authentication factor has been reset — complete re-enrollment or your account will be locked\" emails. The urgency combines loss-of-access fear (can't log into any SSO app) with a tight deadline. In 2025-2026, Okta phishing kits on dark markets include pixel-perfect Okta Verify enrollment pages that capture both credentials and TOTP codes in real-time. The signal fires when: (1) body references Okta brand (Okta, FastPass, Okta Verify, Okta SSO) AND (2) re-enrollment or factor-reset urgency is present AND (3) sender domain is NOT okta.com or *.okta.com AND (4) no List-Unsubscribe. Source: GC1 R14 council #2; Okta 2023 breach post-mortem; Cloudflare Okta phishing campaign disclosure.","tier":"danger","category":"phishing","isThin":false}}