Okta FastPass blocks phishing authentication attempts via MFA

Alerts on Okta FastPass MFA failures where the declined reason indicates a known phishing attempt.

FreeReviewedSigma · High · v4
Product
okta
Service
okta
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2023-05-07
Updated
2026-07-31

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies Okta authentication events where MFA using FastPass is declined with the reason "FastPass declined phishing attempt". Attackers attempting to use known phishing pages are likely to trigger this failure behavior, making it a useful signal for initial access attempts. It relies on Okta System Log telemetry fields including event type, outcome result, and outcome reason.

Related detections9 linkedT1566 — drag to rearrange
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Suspicious AWS Console AiTM Phishing Kit API Endpoints
Suspicious PowerShell Download of updserc Archive to AppData via ClickFix
AWS CloudTrail SSM SendCommand Successful Execution for Instance
Proxy WebDAV MiniRedir Drives Execution from External Shares
Windows WebDAV Temporary File Creation with Suspicious Extensions
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Suspicious Process Execution by Microsoft OneNote on Windows Child Programs
Windows DLL Search Order Hijacking: Suspicious DLL Writes to App Dependency Folders
Okta FastPass blocks phishing authentication attempts via MFA
Pivot detection · T1566 · 9 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.