Executive summary

Okta Threat Intelligence (OTI) recently hit a significant milestone: we sent our 10,000th suspicious domain notification to a customer. 

I wanted to mark the moment by explaining how and why we do this important work.

I also want to share some research we’ve done to prove just how unique these notifications are. The vast majority (over 80%) of the indicators of compromise we identify and share in these customer notifications are not available anywhere else in the world at the time.

Why we go the extra mile

Okta’s vision is to free everyone to safely use any technology, and OTI plays an active role in advancing that goal. Okta is the world's largest independent identity provider and we take very seriously the obligations that come with that position. 

OTI is a multidisciplinary team of security practitioners dedicated to researching, tracking, and mitigating threats. We provide insight, expert advice, and support to our customers and the broader community. 

Every minute of every day, threat actors around the world seek to attack organizations in high threat industries. Their motives vary wildly, from financial gain to state-sponsored espionage. As the identity provider of choice for some of the world's most secure and sensitive organizations, Okta is well positioned to detect, track, and mitigate identity-centric threats. 

Our investigations typically start by tracking the internet infrastructure that threat actors stand up as part of wider campaigns to socially engineer users. We also gain insights and tip-offs from our customers and like-minded organizations, both sharing and receiving threat intelligence to build a collective understanding of threats. No one organization can do this alone. We each hold a piece of the larger picture of how threat actors operate, and sharing it is vitally important.

Our published investigations into novel operator-controlled phishing panels like Work Panel and AitM phishing platforms like VoidProxy are two examples that come to mind where our work not only enumerated attacker infrastructure, but also helped explain to the world how these threats work.

Security notifications

The most common of our suspicious activity notifications concern suspicious domain activity and suspicious user account activity.

An Okta Threat Intelligence milestone: 10,000 customer notifications sent

Suspicious domain activity 

We send suspicious domain activity notifications when we identify domain registrations or infrastructure configurations that we assess with confidence to indicate an intent to target an organization Okta protects. We monitor a number of open and commercial sources of intelligence alongside our own platform telemetry to track new infrastructure as threat actors prepare to launch campaigns. When the stars align we are able to provide advanced warning to customers prior to a campaign going live. 

Sometimes the link between a domain or subdomain is explicit. In other cases, the link to a customer organization is more subtle, such as content visible on the site, or contained within the DOM of the phishing page. Where possible, we provide links to URLScan results for a page so a customer security team can analyze the site for themselves.

Suspicious account activity 

We send a separate notification if Okta Threat Intelligence identifies user interaction with infrastructure we associate with threat actors. The use of the word “suspicious” is very deliberate: there are limits to our visibility into what counts as suspicious in a customer's environment. That said, customer feedback over multiple years has provided confidence that these notifications make a real difference, whether as the initial tip-off that starts an investigation or as an additional signal that informs an in-flight response to an incident. Customers often tell us that our early warning allowed them to act before a threat actor could cause harm. There is nothing our team likes to hear more!

These notifications reach customers via their Primary Security Contacts, a role customers can define in the Okta Support Center. These emails provide actionable intelligence, indicators of compromise (IoCs), and advice for a security or identity team to act on to protect themselves and investigate suspicious activity. Where available, we link to threat advisories with more detail on the threat actor, campaign, or TTPs involved.

A unique source of intelligence

A question we're often asked is why we believe the indicators we identify are malicious, since the domains and IP addresses frequently don't report as malicious in VirusTotal, a trusted threat intelligence platform that draws on a wide range of threat intelligence and security vendors.

All indicators identified and tracked by OTI are identified in the course of our own threat investigations and research. We perform this analysis continuously, identifying and tracking clusters of threat activity as they emerge. The result is a distinctive feed of identity-centric threat intelligence. 

We recently performed some analysis on the uniqueness of our IoCs against available data on them in VirusTotal. We wanted to know what share of the indicators we identified were already flagged as malicious in VirusTotal at the time we notified customers.

83% of suspicious IPs Okta Threat Intelligence submits as detections were not available in other public sources at the time they were flagged.

The results were striking: 83% of the indicators that we confirmed as malicious were not previously detected anywhere else. Of the remainder, 14% had only one to four sources, and just 3% had more than four.

Indicators identified by our researchers are fed into Okta Identity Threat Protection (ITP); providing Okta customers with opportunities to set in-line remediations (raise SOC tickets, reset passwords, revoke sessions, etc.) for user interactions with known malicious infrastructure.  

But we don’t stop there. The security of every Okta customer matters to us. We notify the primary security contacts of any Okta customer we see targeted, or that we have reason to believe threat actors are preparing to target, regardless of what Okta product they buy. We sent 736 of these notifications in July 2026 alone. 

We’re here to help

Like many of the world’s largest platform providers, Okta articulates a shared responsibility model to clearly communicate the line between our security responsibilities and those of our customers. We are responsible for the security of the Okta platform, while our customers are responsible for the security of their organizations (tenants). 

Our proactive notifications wave a foot over that line, but we don’t feel we step over it completely. These detections have a strong true positive rate and have led directly to mitigating threats against a large number of customers over five years, something we remain immensely proud of.

And while we can’t always divulge the methodology of how we track these threat actors, know that if you receive one of our suspicious activity notifications, it is as a result of a team of humans working diligently to protect the most important thing to Okta: our customers. 

Continue your identity journey