By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Tech Insight
  • Digital
  • Software
  • Infrastructure
  • Security
  • Data
  • Cloud
  • Research Center
Reading: OneLogin: Another One Bites the Dust
Tech InsightTech Insight
Font ResizerAa
Search
Have an existing account? Sign In
Follow US
© 2024 Tech Insight, a Talk About Tech brand. All rights Reserved.
Tech Insight > Cloud & Edge > Cloud Computing > SAAS > OneLogin: Another One Bites the Dust

OneLogin: Another One Bites the Dust

John Connor
John Connor Cloud Computing Fraud & Identity Theft Malware & threats Privacy SAAS Vulnerabilities
Share
4 Min Read
onelogin
SHARE

The 1980 Queen hit ‘Another One Bites the Dust’ was an anthem for the 80s generation. But it also happens to describe security systems nearly 40 years later. After the massive ransomware attack last week (‘WannaCry’), and Android iOS breach (‘Judy’), another critical breach has been reported by the access management service (AMS) OneLogin.

OneLogin is a major player in the AMS service field. They provide password management for enterprise level clientele. The service is helpful for this client base because it provides a single sign on (SSO) cloud solution for ease and greater levels of security. Their client list is impressive – AAA, Yelp, and Dell, to name a few. Their open source tool kits are being used by more than three hundred venders and seventy software-as-a-service (SaaS) vendors worldwide.

With all this corporate access information, no wonder OneLogin is a target for high-level hacking. Yesterday the company announced that a major malicious attack had occurred on their US operations. The attacker was able to access the AWS API and create a number of instances within the infrastructure. The hacker had seven hours of uninterrupted access.

The company is still determining the extent of the breach, but in their announcement did indicate that some very major events had happened. It appears that the attacker was able to access information about the company’s users including various types of keys, and, far more concerning, was able to decrypt data that was at rest within the archives. This means that the actor was able to find access to the highest level of security, and that OneLogin had apparently left a gaping hole in their system, allowing for a breach of end to end encryption. This sort of breach indicates a substantial concern within the OneLogin system that will raise attention at the highest levels.

The company has provided a guide for securing data that has been breached, which, no doubt, was the task of a substantial part of the corporate IT world this morning. However, the guide simply provides 11 steps to recreating security for breached data, but this does not mean that the hacker, with seven hours of access, has not already obtained and decrypted whatever data was present. At the enterprise level, this is the equivalent of breaking into the CEO’s office and rifling through his desk and personal files for 7 hours. It’s not good.

This is not the first attack on OneLogin.  A previous hack had compromised a substantial amount of data, but encryption was never broken. This current attack has led some in the security world to question how to best secure high level corporate data, given the increasing level of hacker ability. Companies would be wise to be researching different methodologies (both in house and third party), and identifying deeper levels of security risk than the home page of the company offers. OneLogin is a high level security system, and such a hack should make other IT professionals question where safety is even possible at this point. As the Queen ballad reminds us, no one is safe.

TAGGED:judyoneloginransomwaresecuritywannacry

Sign Up For Our Newsletter

Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Twitter LinkedIn Reddit Email Copy Link
Previous Article innovation economy The Best Part of a Sandwich
Next Article Have you ever stood outside under a bright starry-lit sky? It’s an overwhelming experience, and maybe the last thing on your mind is artificial intelligence for astronomy. Artificial Intelligence Helps Us Understand The Universe.
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts

Beyond Revenue & Airbnb Integration Boosts Rental Earnings

Beyond & Airbnb Integration Boosts Rental Earnings

Conal Cram 3 Min Read
Malicious AI

Malicious AI Use Could Cause ‘Unimaginable’ Damage, Warns UN Secretary General

Conal Cram 4 Min Read
Reddit Announces IPO Filing — Finally.

Reddit Announces IPO Filing — Finally.

Conal Cram 4 Min Read
McKinsey and Salesforce Forge Ahead with AI-powered Venture

McKinsey and Salesforce Forge Ahead with AI-powered Growth Collaboration

Conal Cram 5 Min Read

From our research center

KnowBe4 Africa (Pty) Ltd

10 Questions Every CISO Should Ask About AI-Powered Human Risk Management Tools

AI is transforming security awareness—but how much is marketing hype versus genuine value for your organisation? Human risk management (HRM) and security awareness vendors of...

Read content
  • About us
  • Contact us
  • Research Center
  • Disclaimer
  • Privacy
  • Terms & Conditions

We Are Tech Insight

We have been delivering breaking news from the tech world since 2017. Our goal is to help you stay up-to-date with the latest developments, trends, and breakthroughs in the tech world.

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site..

Read our privacy policy for more information.

© 2025 Tech Insight, a Talk About Tech brand. All rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?