Cloudflare hacked using auth tokens stolen in Okta attack
ID: 5b446357-40d2-5277-999d-19400f595818
STIX ID: report--5b446357-40d2-5277-999d-19400f595818
Feed Name: Bleeping Computer
Cloudflare disclosed that a suspected nation-state attacker leveraged credentials stolen during the Okta breach to access its self-hosted Atlassian servers (Confluence, Jira, Bitbucket) in November 2023, viewed architecture and security documentation and a limited amount of source code, attempted to establish persistence and access a São Paulo data center, and was detected and removed after which Cloudflare rotated credentials, reimaged affected systems, and reports no customer data or services were impacted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
