See this blog post (linked in original article) from a security firm that was one of Okta's customers, and alerted them to the breech, when they detected suspicious activity on their network shortly after sharing the HAR file with Okta:
https://www.beyondtrust.com/blog/entry/okta-support-unit-bre...