Cloudflare has confirmed a security incident involving unauthorized access to its internal Atlassian server, which hosted a wiki, bug database, and git repositories. The company stated that the attack was sophisticated and targeted, leveraging a stolen credential to breach the system. The credential, described as a service token, was not protected by multifactor authentication and was compromised during a previous breach at Okta in October 2023. This token was then used to access the Atlassian systems on November 14, 2023.
The attackers maintained access to Cloudflare's Atlassian environment for a period before being detected. Cloudflare initiated an investigation immediately upon discovering the intrusion, which included forensic analysis and a review of system logs. The company confirmed that the attackers attempted to access a console server, which was a critical internal system, but this attempt was unsuccessful.
Following the detection of the breach, Cloudflare took several steps to mitigate the impact and secure its systems. These actions included rotating over 5,000 production credentials, segmenting its internal Atlassian server from the rest of its network, and enhancing its security monitoring capabilities. The company also implemented new hardware security keys for all employees and conducted a comprehensive audit of its internal systems to identify and address any remaining vulnerabilities.
Cloudflare emphasized that its customer-facing systems and data were not affected by this incident. The company's core services, including its CDN, DNS, and security offerings, continued to operate without interruption. The breach was confined to the internal Atlassian environment, which is used for development and project management.
The incident highlights the ongoing challenges organizations face in securing their supply chains and internal systems against sophisticated attackers. The use of a credential stolen from a previous breach underscores the importance of robust credential management and the widespread adoption of multifactor authentication across all internal and external services. Cloudflare's rapid response and transparency in reporting the incident are consistent with industry best practices for managing security breaches.






