Cloudflare reported Feb. 1 that it was the victim of a nation-state attack on its Atlassian systems following last fall’s Okta breach.While the attack started in October when Okta was compromised, Cloudflare said in a blog post that the bad actor started targeting its systems with the Okta credentials in mid-November — credentials that should have been rotated.“Unfortunately, we failed to rotate one service token and three service accounts (out of thousands) of credentials that were leaked during the Okta compromise,” wrote the Cloudflare researchers.Cloudflare’s researchers said from Nov. 14 to 17, the threat actor accessed Cloudflare’s “internal wiki,” which uses Atlassian Confluence, and the cloud provider’s bug database — Atlassian Jira.According to the researchers, the threat actor returned on Nov. 22 and established access to Cloudflare’s Atlassian server using ScriptRunner for Jira, gaining access to Cloudflare’s source code management system. Over the next day, the threat actor viewed 120 code repositories and of the 120 repos, the threat actor used the Atlassian Bitbucket git archive feature on 76 and downloaded them to the Atlassian server.“Even though we were not able to confirm whether or not they had been exfiltrated, we decided to treat them as having been exfiltrated,” wrote the researchers. “The 76 source code repositories were almost all related to how backups work, how the global network is configured and managed, how identity works at Cloudflare, remote access, and our use of Terraform and Kubernetes.”CrowdStrike, which was brought in to assist in the remediation efforts, confirmed that the last evidence of threat activity was on Nov. 24 at 10:44 UTM.
Identity, Breach, Threat Intelligence

Cloudflare’s Atlassian systems breached in nation-state attack
Cloudflare said it suffered an attack after failing to rotate credentials. (Adobe Stock)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds