Cloudflare has confirmed a security incident involving unauthorized access to its internal Atlassian server, which hosted its Confluence wiki, Jira bug-tracking system, and Bitbucket source code management. The company stated that the attack was highly targeted and sophisticated, carried out by a nation-state actor.
The breach was detected on October 26, 2023, when Cloudflare identified a threat actor using stolen credentials to access its self-hosted Atlassian instance. The attackers leveraged a "social engineering attack" to obtain an employee's credentials, which were not protected by multi-factor authentication (MFA). This initial access allowed them to penetrate Cloudflare's internal network.
Once inside, the attackers established persistent access using a new identity provider account and then attempted to access a console server. Cloudflare's security team detected these activities and initiated an investigation. The company subsequently rotated over 5,000 production credentials, segmented its test and staging environments, and implemented new hardware security keys.
Cloudflare's investigation revealed that the attackers accessed documentation and a limited amount of source code. Specifically, they accessed the Confluence wiki, Jira bug database, and Bitbucket source code repositories. The company confirmed that no customer data or systems were affected, and there was no impact on its global network or customer-facing products. The attackers did not gain access to Cloudflare's global network, customer data, or production systems.
The threat actor's objective appeared to be gaining persistent access to Cloudflare's network and specific data. The company has not publicly named the nation-state actor responsible but has indicated that the attack was part of a broader campaign targeting multiple technology companies.
Cloudflare emphasized that the incident was contained due to its robust security measures, including network segmentation and rapid response protocols. The company has since enhanced its internal security posture, including mandating the use of hardware-backed security keys for all employees and further strengthening its monitoring and detection capabilities.






