Two years ago, Okta's own security chief said the quiet part out loud: "We need a track record of zero breaches. That's what builds trust. The score sheet for us needs to be a clean sheet — zero for the next few years." It was an extraordinary admission from the company that holds the front-door keys for 20,000 organizations, and it set a clock running. This week, with Okta posting its strongest financials in years and a stock that's clawed back most of what the 2023 breach cost it, the question is simply: is the sheet clean?
That's the spotlight this issue — Okta, the identity incumbent that got breached at the worst possible moment for an identity company, and has spent two years trying to earn back the one thing it sells. The financials say recovery. The product reviews say "still the standard." The scar tissue, and a live fight over Auth0 pricing, say do your reading first. Plus a month of market movers, led by a $60M bet that the whole category needs replacing. Let's get into it.
the last week, distilled — & why it lands on your desk
Tel Aviv's Oak launched with a $60M seed co-led by Accel, Greylock, and CRV — an unusually large seed, and a telling one. Founder Shai Morag has sold three prior security startups (to Mellanox, Palo Alto, and Tenable), and Oak's pitch is blunt: cloud-era IAM tools were built for a human-only enterprise, and they can't track who — or what — accesses what once AI agents proliferate. It arrived already generally available and deployed at enterprises.
The US auto insurer disclosed a breach affecting up to 6.9 million people, exposing names, contact details, driver's license numbers, and policy data. TechCrunch called it the largest known exposure of driver's license numbers so far in 2026. The root cause, again: compromised employee credentials — not an exotic exploit.
Barracuda acquired Evo Security, an IAM provider built specifically for managed service providers, folding privileged access, identity protection, and ITDR into its BarracudaONE platform. It's a signal that identity consolidation isn't just an enterprise game — the MSP channel, which secures much of the mid-market, is being rolled up too. Meanwhile Europe saw Fourthline and Veridas announce a merger to form an identity-verification heavyweight.
A new WatchGuard global survey finds shadow AI and unsafe work habits are creating significant, largely unseen risk — employees feeding data into unsanctioned AI tools, reusing credentials, and sidestepping controls. It lands alongside separate reporting on "ghost workers" and hiring deception, where weak identity and skills verification let bad actors into the workforce itself.
Security researchers this month described what they're calling the first ransomware operation run end-to-end by an AI agent — reconnaissance, access, and deployment with minimal human steering. Paired with a wave of AI-agent exploitation stories (OpenClaw agents abused via WhatsApp), the "autonomous attacker" moved from thought experiment to case study.
A ransomware crew posted what it claims is proof of a Deutsche Bank compromise, raising extortion pressure on one of the world's largest banks; the D1R group separately claimed data from Synopsys and Bosch. Whether or not every claim holds, the tactic — public "proof" to force a negotiation — is now standard operating procedure.
the pitch vs. the reality, synthesized from the people who run it
Okta closed FY2026 at roughly $2.88B in revenue (11% YoY), with non-GAAP operating margin around 25–26% and strong free cash flow — a genuine turn for a company that hadn't posted a quarterly profit since its 2017 IPO. Recent quarters beat consensus handily (Q1 FY27 EPS $0.91 vs. $0.74 expected), current RPO grew double digits, and 20,000+ customers now include large public-sector wins. Market cap sits near $18B.
Okta has spent the last year expanding beyond its front-door heritage: Okta Identity Governance (OIG), Privileged Access, and the acquisition of Axiom Security for SaaS security-posture management and real-time session monitoring. Add early AI-agent security products drawing outsized deal sizes, and the pitch is a single unified platform — neutral and independent, not tied to a cloud or productivity suite.
Okta's recent history is defined by security failures at the worst possible place for an identity company: a 2022 LAPSUS$ intrusion and stolen GitHub source code, then the 2023 support-system breach that Okta first pegged at ~1% of customers before conceding, weeks later, that 100% of its ~18,400 support customers were exposed. BeyondTrust and Cloudflare detected it before Okta did. Security chief David Bradbury's response set the bar: "We need a track record of zero breaches… the score sheet needs to be a clean sheet for the next few years."
Okta's developer-identity arm, Auth0, draws consistent fire on cost. G2's top negative tags include "Expensive," "Cost," and "Expensive Pricing"; multiple reviewers cite a jarring price increase (one widely-referenced review calls a ~300% jump "hostile/predatory") and renewals that doubled. Per-user costs escalate steeply as you scale, and enterprise features sit behind higher tiers. A separate verified review flagged unanswered support on a critical issue.
Trajectory: a strong core, an unproven expansion. Strip away the history and Okta's workforce heritage is genuinely excellent: category-leading SSO and MFA (G2 4.5), a real neutrality advantage over a bundled Microsoft Entra, and — finally — the financials of a durable public company. But the platform story Okta is now selling — governance, PAM, and Agent Security bundled in as "one platform" — leans heavily on products that are newer and thinner-proven, with limited GA track record next to the 15-year-old SSO core. That gap is why the product score sits at 7.6 rather than higher: the foundation is excellent, but you're being sold a platform, and part of that platform hasn't been tested at scale yet.
But you can't strip away the history, and for an identity vendor you shouldn't. Okta got breached at the one place a security company can least afford it, more than once, and the 2023 incident's "1% → 100% of customers" revision — caught by BeyondTrust and Cloudflare before Okta's own detection — is exactly the kind of thing that makes a CISO keep independent monitoring on their own IdP. That's why we broke out Trust & Track Record as its own score and marked it 6.4 while everything else sits high. Add a consistent employee signal — strong product and smart people, but "constant pivots" and "off-the-cuff CEO/CRO decisions" that nudged our stability read down too — and the picture is a capable platform whose steering is worth watching. The recovery is real; so is the scar tissue and the internal churn. All of it is true at once.
The live, practical gripe is Auth0 pricing. If you're building customer identity, model costs at 2–3x your current user count and get renewal caps in writing — the "300% increase" reviews aren't outliers, they're a pattern. Net: a strong buy on capability, a "verify the security posture yourself" on trust, and a "read the contract twice" on cost. For a multi-cloud shop that values neutrality, that can still be the right answer — with eyes open.
a category, tool, or idea worth knowing this week
With most software, a past breach is a footnote. With the vendor that holds your authentication, it's central — because the failure mode is your entire access layer. When you evaluate an identity provider, weight their track record and, crucially, their disclosure behavior (did they tell customers, or did customers tell them?) as heavily as the feature matrix. Then keep independent monitoring on your IdP regardless of who it is.
Oak's $60M seed is the loudest of several bets on the same gap: as AI agents proliferate, nobody can answer "which agent accessed what, and when?" Legacy IAM was built to map humans to apps, not agents to tools. Whether you buy a startup or press your incumbent, get a straight answer on how non-human and agent access is discovered and governed — not just authenticated.
The Deutsche Bank "evidence" post is this week's reminder: attackers now weaponize the disclosure itself, dropping partial "proof" to panic your board before your IR team has facts. A pre-agreed verification-and-comms playbook — who confirms, who speaks, what you say before you know — is what keeps an unverified claim from becoming its own crisis.
one line to sound three moves ahead in your next exec meeting
Every identity provider will show you a feature matrix. Fewer will volunteer their breach history and — more tellingly — how they found out about it. When you're picking the vendor that holds the keys to everything, their disclosure behavior under pressure is a better predictor of your future incident experience than any capability chart. Make it an explicit evaluation criterion, not an awkward afterthought.
a spicy anonymized take from the community this week