{"slug": "shadow-ai-agents-stalking-networks-undetected-okta-chief-warns", "title": "‘Shadow’ AI agents stalking networks undetected, Okta chief warns", "summary": "Okta president and COO Eric Kelleher warned that Australian companies have lost track of AI agents operating on their networks, with employees creating 'shadow' agents via generative AI without IT knowledge, increasing data breach risks. He noted that these agents run 24/7 and may have standing access, and urged companies to limit access and use biometric multi-factor authentication, citing that SMS-based MFA is vulnerable to phishing.", "body_md": "# ‘Shadow’ AI agents stalking networks undetected, Okta chief warns\n\nAustralian companies have lost track of the artificial intelligence agents crawling through their own networks – and cannot say what those agents are allowed to access, according to identity management and security titan Okta.\n\nPresident and chief operating officer of the US$25.6bn company Eric Kelleher also warned that not all multi-factor authentication was equal and could be vulnerable to phishing hacks, and expressed concern about China’s TikTok and Alibaba looking to [develop data centres in Australia.](https://www.theaustralian.com.au/business/headed-to-firb-bytedances-tiktok-seeks-data-centre-partner-while-alibaba-shops-for-gas-power/news-story/6181a7a7ac204e7d573b14d2ecec9f0b)\n\nKelleher said staff were ‘vibe coding’ their own ‘agents’ – via basic verbal prompts thanks to generative AI – and switching them on without telling anyone, heightening the risk of data breaches and cyber attacks.\n\n“There isn’t a default announcement when an employee turns on an agent that all of a sudden my CIO (chief information office) knows that that’s happened,” Kelleher told The Australian.\n\n“They don’t work eight-hour days. These autonomous agents run 24-seven. They don’t take vacations. They don’t take sick leave, and they have access.”\n\nAustralia’s peak cyber security agency has warned of Russian hackers targeting hospitals and critical infrastructure after Moscow’s spies harvested passwords from companies which hadn’t been changed from their default settings for years, while the conflict in Iran has also fuelled more Tehran-sponsored online attacks.\n\nIn the past year, Australia’s biggest industry superannuation funds have been breached after they failed to switch on multi-factor authentication, while last month Origin Energy said[ at least 900,000 customer records](https://www.theaustralian.com.au/business/technology/origin-energy-says-its-initial-review-has-found-900000-customers-hit-by-major-data-breach/news-story/183ba1a29c36f018e279a4e0b3ddecb7) were accessed illegally after a self-style hacker said they used an employee login to access the utility’s database.\n\nBut, Kelleher said the employee login at the centre of Origin’s breach wasn’t the main question. It was about access and, as more companies switch on AI-powered agents, the risk increases.\n\n“An agent shouldn’t have perpetual access, standing access to that data. It should be turned on when you need to use the agent, and then turned off. So it’s not sitting on, 24-seven, waiting to be compromised by a threat actor,” he said.\n\n**Need to limit access**\n\nCompanies must also limit staff access to sensitive information to levels necessary to do their jobs. Qantas imposed such caps after about five million of its customer records were stolen last year after hackers targeted one of its support centres in Manila.\n\n“We process over 45 billion authentication transactions every month, and in that volume, we see suspicious activity for threat actors that are trying to impersonate. And so, one of the pieces of value we can provide for our customers is helping them identify anomalies from threat actors that are attacking other customers or that are active elsewhere,” Kelleher said.\n\nHe said multi-factor authentication (MFA) could also be hacked via social engineering and phishing – cyber criminals trying to trick employees for verification codes.\n\n“If you’re still sitting on SMS tokens for multi-factor, you’re waiting to get breached,” Kelleher said.\n\n“What you’ll find in many of these public breaches that are published is either the enterprise had not deployed multi-factor at all, or they had deployed multi-factor in only some use cases, and they targeted users that were not covered under multi-factor, or they’ve deployed multi-factor using what I’ll call legacy tokens, things like an email link or an SMS link, which can be phished.”\n\n**Incorporate MFA**\n\nKelleher urged incorporating biometrics into MFA but said there is a “human readiness” problem that’s hardware-based – having computers and smartphones that can scan fingerprints and faces – and psychological.\n\n“I’ve been at Okta for 10 years, and I don’t know my password. I authenticate through facial recognition, and on my laptop I authenticate through fingerprints.\n\n“The technology is ready today for passwords to be gone. The limitation is not technology readiness; it’s human readiness. And so, people being willing to fully embrace and understand passkeys.”\n\nAnd this is where AI agents again pose a problem – they have no fingerprints and no face. They log in using encrypted tokens, which Kelleher said were issued once and almost never changed, and copied, pasted and buried in script files in plain text, where anyone can read them.\n\n“So just like how you have to change your password every 90 days, the tokens need to be rotated,” Kelleher said.\n\nHe expressed concern about TikTok and Alibaba looking to develop data centres in Australia and said the US had strict regulations to “minimise” such investment from Chinese companies.\n\n“I’m not sure specifically about Australia’s activity in that area, but I would imagine they also were looking at ways to restrict the potential access Chinese companies would have to sovereign data on Australian soil being embedded in data centres,” he said.\n\n“We all need to be very careful about that.”\n\n*This article first appeared in The Australian as **‘Shadow’ AI agents are stalking Australian networks undetected, security chief warns**.*\n\n## Related Topics\n\n### UNLOCK INSIGHTS\n\nDiscover the untold stories of emerging ASX stocks.\n\nDaily news and expert analysis, it's free to subscribe.\n\nBy proceeding, you confirm you understand that we handle personal information in accordance with our\n[Privacy Policy](https://stockhead.com.au/privacy-policy/).", "url": "https://wpnews.pro/news/shadow-ai-agents-stalking-networks-undetected-okta-chief-warns", "canonical_source": "https://stockhead.com.au/tech/shadow-ai-agents-stalking-networks-undetected-okta-chief-warns/", "published_at": "2026-08-12 05:39:51+00:00", "updated_at": "2026-08-12 06:09:55.312857+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy"], "entities": ["Okta", "Eric Kelleher", "Origin Energy", "Qantas"], "alternates": {"html": "https://wpnews.pro/news/shadow-ai-agents-stalking-networks-undetected-okta-chief-warns", "markdown": "https://wpnews.pro/news/shadow-ai-agents-stalking-networks-undetected-okta-chief-warns.md", "text": "https://wpnews.pro/news/shadow-ai-agents-stalking-networks-undetected-okta-chief-warns.txt", "jsonld": "https://wpnews.pro/news/shadow-ai-agents-stalking-networks-undetected-okta-chief-warns.jsonld"}}