It appears they’ve had access since at least January. I wonder how many customer accounts have been breached? It’s a giant list of targets if so.
It’s also very disappointing this is surfacing via tweets and not a breach notice from Okta, who apparently suspended at least one account used for entry.