Cloudflare Falls Victim to Okta Breach, Atlassian Systems Cracked
ID: 0c155d89-ab0b-5b50-8bb5-9a4db9c60ebf
STIX ID: report--0c155d89-ab0b-5b50-8bb5-9a4db9c60ebf
Feed Name: Dark Reading
Date Published: 2024-02-02
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Cloudflare disclosed that it was targeted in the Okta supply-chain campaign in late November, with attackers accessing internal Atlassian services (Confluence, Jira, Bitbucket) and an AWS instance to look for network configuration, secret rotation, and MFA-bypass information. The company, working with CrowdStrike, attributes the activity to a nation-state actor, found evidence of lateral movement and persistence, and reports that some documentation and limited source code were accessed but no customer data; Cloudflare rotated over 5,000 credentials and reimaged nearly 4,900 systems as remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
