Cloudflare, the internet infrastructure and security company, has confirmed that a recent security incident involved unauthorized access to its internal Atlassian server. The company stated that the compromise was limited to its Confluence wiki, Jira bug-tracking system, and Bitbucket source code management system, which are used for internal documentation, project tracking, and code repositories.
The incident was first detected on November 14, 2023, when Cloudflare's security team identified a threat actor accessing its self-hosted Atlassian environment. The attacker leveraged a stolen credential to gain initial access. This credential was obtained from a previous compromise of an employee's personal account and was not protected by multi-factor authentication (MFA) at the time of the initial breach.
Upon discovering the unauthorized activity, Cloudflare initiated an immediate investigation and containment process. The company confirmed that the attacker accessed its Confluence, Jira, and Bitbucket systems. Specifically, the attacker gained access to a limited number of source code repositories within Bitbucket.
Cloudflare emphasized that the incident did not impact its customer-facing systems or data. The company's products and services, including its global network and customer data, remained secure and operational throughout the event. There was no evidence of data exfiltration from customer systems or any compromise of Cloudflare's production environment.
The company's internal investigation revealed that the attacker attempted to access a console server and a system that housed a digital certificate signing key. However, these attempts were unsuccessful due to Cloudflare's robust security controls and the implementation of hardware security keys, which prevented the attacker from gaining further access or exfiltrating sensitive cryptographic material.
Cloudflare has taken several steps to mitigate the impact of the breach and enhance its security posture. These actions include rotating all potentially compromised credentials, conducting a comprehensive review of its internal systems, and reinforcing its multi-factor authentication policies across all employee accounts. The company also confirmed that it has notified relevant regulatory authorities and law enforcement agencies about the incident.






