logo

Cloudflare hacked using auth tokens stolen in Okta attack

ID: daeabb4c-9b24-597f-9723-7c1eab14fce9

STIX ID: report--daeabb4c-9b24-597f-9723-7c1eab14fce9

Feed Name: DataBreaches.Net

Threat Score
70/100

Date Published: 2024-02-02

Date Updated: 2026-04-19

Author: Dissent

...
...

Cloudflare disclosed a breach of its self-hosted Atlassian server by a suspected nation-state actor, who accessed Confluence, Jira, and Bitbucket, established persistence via ScriptRunner for Jira, and attempted (unsuccessfully) to access a console server tied to a not-yet-live São Paulo data center. The incident involved reconnaissance, return access on November 22, and interaction with source code management systems, as detailed by Cloudflare leadership and referenced by BleepingComputer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.