Lighthouse is a phishing software service described in the lawsuit [PDF] as a "phishing for dummies" kit. Criminals pay a monthly subscription fee for access to hundreds of templates for fake websites, domain set-up tools for those phony sites, and other features designed to dupe victims into believing they are visiting a legitimate website. The crims use these sites to trick victims into entering their financial info and other sensitive details, which the crooks then steal.
The phishes target any Google and Microsoft accounts, from small businesses to large enterprises, we're told. And while Okta didn't have a confirmed victim count, "we have observed high-confidence account takeovers in multiple entities," the threat intel team told us. "By extension, we expect Microsoft and Google will have observed a larger number of ATO events, given that VoidProxy proxies non-federated users directly with Microsoft and Google servers."