logo

Cloudflare hacked using auth tokens stolen in Okta attack

ID: 5b446357-40d2-5277-999d-19400f595818

STIX ID: report--5b446357-40d2-5277-999d-19400f595818

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-02-01

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cloudflare disclosed that a suspected nation-state attacker leveraged credentials stolen during the Okta breach to access its self-hosted Atlassian servers (Confluence, Jira, Bitbucket) in November 2023, viewed architecture and security documentation and a limited amount of source code, attempted to establish persistence and access a São Paulo data center, and was detected and removed after which Cloudflare rotated credentials, reimaged affected systems, and reports no customer data or services were impacted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.