Cloudflare
Disclosed Feb 1, 20242 years agoConfirmed
Nation-state actor uses Okta-stolen tokens to breach Cloudflare Atlassian systems
Cloudflare said a suspected nation-state attacker used a token and service account credentials stolen in the October 2023 Okta breach, which Cloudflare had not rotated, to access its internal Confluence wiki, Jira and Bitbucket source code in November 2023. No customer data or systems were affected.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Feb 1, 2024 |
| Discovered | Nov 23, 2023 |
| Attack | Hacking |
| Data exposed | Internal documents, Source code, Credentials and tokens |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Thanksgiving 2023 security incident (Cloudflare Blog)blog.cloudflare.com · The organization | The organization |
| Cloudflare breached on Thanksgiving Daysecurityaffairs.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Feb 1, 2024 |
Other breaches at Cloudflare
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Cloudflare Salesforce data stolen via Salesloft Drift OAuth tokensSep 2, 20251 year agoSupply chain | Sep 2, 20251 year ago | Supply chain | Tech | Confirmed | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.