Cloudflare has confirmed a security incident involving unauthorized access to its internal Atlassian server, which hosts its Confluence wiki, Jira bug-tracking system, and Bitbucket source code management. The company stated that a suspected state-sponsored attacker gained access to the server on October 14, 2023, by compromising an employee's credentials.
The attacker reportedly used these compromised credentials to access a Cloudflare employee account, which did not have multi-factor authentication (MFA) enabled. This initial access allowed the threat actor to pivot to the internal Atlassian server. Cloudflare indicated that the attacker attempted to access a console server and its Atlassian systems on October 26, but these attempts were blocked.
On November 22, the attacker successfully accessed the Atlassian server. Cloudflare detected the breach on November 24 and initiated an investigation. The company subsequently rotated over 5,000 production credentials, segmented its internal Atlassian server from its corporate network, and reset credentials for all employees.
According to Cloudflare, the attacker accessed its Confluence wiki and Jira systems, and also gained access to its Bitbucket source code repositories. The company reported that the attacker downloaded 76 repositories, including those containing system architecture diagrams, database schemas, and information about its identity and access management. Cloudflare emphasized that no customer data or systems were impacted by this breach.
The company's investigation revealed that the attacker had been persistent, attempting to establish a foothold in Cloudflare's network for several months. The threat actor reportedly used a stolen credential to access Cloudflare's systems, targeting a specific employee. Cloudflare has not publicly identified the state-sponsored group responsible for the attack, but the company's security team is actively collaborating with law enforcement agencies on the ongoing investigation.
Cloudflare has stated that the incident did not compromise its global network, its edge network, or any customer-facing services. The company has also confirmed that its core infrastructure, including its DNS, CDN, and security services, remained secure and operational throughout the incident. Cloudflare has committed to providing further updates as its investigation progresses.






