Okta Inc (NASDAQ:OKTA) extended Friday’s falls after the firm said attackers accessed files containing cookies and session tokens uploaded by customers to its support-management system.
After falling 11% on Friday, Okta shares tumbled another 8% on Monday after the identity and access management company said it had identified "adversarial activity that leveraged access to a stolen credential to access Okta's support case-management system."
All told, the two days of losses erased more than $2 billion of Okta's market cap.
In a statement, Okta chief security officer David Bradbury said the hackers were "able to view files uploaded by certain Okta customers as part of recent support cases. It should be noted that the Okta support case management system is separate from the production Okta service, which is fully operational and has not been impacted."
Okta was famously targeted by the Lapsus$ hacking group, alongside Microsoft, in March 2022, with internal documents stolen.
In that case, the hack had taken place in January but was not disclosed until March and only when Lapsus$ went public with the details.
Analysts on Monday did not respond positively to the news of the fresh cyber attack, with Citi analysts adding the stock to their downside 90-day catalyst watch list, citing "possible narrative/sentiment overhang inhibiting multiple expansion, and the potential for reputational risk affecting new pipeline development, platform expansion activity, and churn/retention dynamics."
Evercore ISI analysts also put Okta on their tactical underperform list "rooted in our concern that these events will most likely have a [near-term] impact on OKTA’s pipelines, potentially forcing a downward revision to 2024 financial year estimates and jeopardizing consensus estimates."
- Updated with share price movement and analyst comments -