Cloudflare has confirmed that it was targeted by a nation-state attacker in November 2023, with the incident involving a highly sophisticated attempt to gain persistent access to its systems. The company disclosed that the attacker, identified as a nation-state actor, exploited a zero-day vulnerability in Atlassian Confluence Data Center and Server to breach its self-hosted Atlassian server. This vulnerability, tracked as CVE-2023-22518, allowed the attacker to create a new administrator account on the Confluence instance.
The initial compromise occurred on November 14, 2023, when the attacker accessed Cloudflare's Confluence server. From there, they moved laterally to Cloudflare's Jira system, another Atlassian product, and then to a physically separate Atlassian Bitbucket server. The attacker used the newly created administrator account to access internal wiki pages, bug database information, and source code management systems.
Cloudflare detected the intrusion on November 23, 2023, when its security team observed the attacker attempting to access a console server that was not part of the Atlassian suite. This attempt triggered an alert, leading to an immediate investigation. The company's incident response team then initiated a comprehensive containment and eradication effort.
The attacker's objective appeared to be establishing persistent access to Cloudflare's network. They attempted to use stolen credentials to access Cloudflare's Atlassian systems, as well as its data centers and a console server. Cloudflare confirmed that the attacker did not gain access to its customer data or its global network. The company also stated that no customer systems or data were impacted during the incident.
In response to the attack, Cloudflare rotated over 5,000 production credentials, including secrets, certificates, and service tokens. They also segmented their network further and enhanced monitoring capabilities. The company emphasized that the attack was highly targeted and leveraged advanced persistent threat (APT) techniques, characteristic of nation-state operations.
Cloudflare's investigation revealed that the attacker had been present in their Atlassian environment for approximately nine days before detection. The company has since patched the exploited Confluence vulnerability and implemented additional security measures to prevent similar incidents. They also worked with law enforcement agencies in their investigation.






