Skip to content

Cloudflare

Disclosed Feb 1, 20242 years agoConfirmed

Official notice

Nation-state actor uses Okta-stolen tokens to breach Cloudflare Atlassian systems

Cloudflare said a suspected nation-state attacker used a token and service account credentials stolen in the October 2023 Okta breach, which Cloudflare had not rotated, to access its internal Confluence wiki, Jira and Bitbucket source code in November 2023. No customer data or systems were affected.

What is known

People affectedNot stated in the sources we have
DisclosedFeb 1, 2024
DiscoveredNov 23, 2023
AttackHacking
Data exposedInternal documents, Source code, Credentials and tokens
SectorTech · US
StatusConfirmed

Sources

Source
Thanksgiving 2023 security incident (Cloudflare Blog)blog.cloudflare.com · The organization
Cloudflare breached on Thanksgiving Daysecurityaffairs.com · News

Notices filed

WhereFiledPeople
ResearchtotalFeb 1, 2024

Other breaches at Cloudflare

BreachAffected
Cloudflare Salesforce data stolen via Salesloft Drift OAuth tokensSep 2, 20251 year agoSupply chainUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Cloudflare

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.