Cloudflare Breach: Nation-State Hackers Access Source Code and Internal Docs

Share:

Cloudflare has revealed that it was the target of a likely nation-state attack in which the threat actor leveraged stolen credentials to gain unauthorized access to its Atlassian server and ultimately access some documentation and a limited amount of source code.

The intrusion, which took place between November 14 and 24, 2023, and detected on November 23, was carried out “with the goal of obtaining persistent and widespread access to Cloudflare’s global network,” the web infrastructure company said, describing the actor as “sophisticated” and one who “operated in a thoughtful and methodical manner.”

As a precautionary measure, the company further said it rotated more than 5,000 production credentials, physically segmented test and staging systems, carried out forensic triages on 4,893 systems, reimaged and rebooted every machine across its global network.

The incident involved a four-day reconnaissance period to access Atlassian Confluence and Jira portals, following which the adversary created a rogue Atlassian user account and established persistent access to its Atlassian server to ultimately obtain access to the Bitbucket source code management system by means of the Sliver adversary simulation framework.

As many as 120 code repositories were viewed, out of which 76 are estimated to have been exfiltrated by the attacker.

“The 76 source code repositories were almost all related to how backups work, how the global network is configured and managed, how identity works at Cloudflare, remote access, and our use of Terraform and Kubernetes,” Cloudflare said.

“A small number of the repositories contained encrypted secrets which were rotated immediately even though they were strongly encrypted themselves.”

The threat actor is then said to have unsuccessfully attempted to “access a console server that had access to the data center that Cloudflare had not yet put into production in São Paulo, Brazil.”

The attack was made possible by using one access token and three service account credentials associated with Amazon Web Services (AWS), Atlassian Bitbucket, Moveworks, and Smartsheet that were stolen following the October 2023 hack of Okta’s support case management system.

Cloudflare acknowledged that it had failed to rotate these credentials, mistakenly assuming they were unused.

The company also said it took steps to terminate all malicious connections originating from the threat actor on November 24, 2023. It also involved cybersecurity firm CrowdStrike to perform an independent assessment of the incident.

“The only production systems the threat actor could access using the stolen credentials was our Atlassian environment. Analyzing the wiki pages they accessed, bug database issues, and source code repositories, it appears they were looking for information about the architecture, security, and management of our global network,” Cloudflare said.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:53 am, Jan 22, 2025
weather icon 3°C
L: 3° | H: 5°
overcast clouds
Humidity: 91 %
Pressure: 1005 mb
Wind: 3 mph NNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 7 km
Sunrise: 7:52 am
Sunset: 4:31 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
3° | 5°°C 0 mm 0% 4 mph 91 % 1004 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
2° | 8°°C 1 mm 100% 16 mph 91 % 1005 mb 0 mm/h
Fri Jan 24 9:00 pm
weather icon
6° | 10°°C 1 mm 100% 23 mph 90 % 1004 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
4° | 6°°C 0.93 mm 93% 9 mph 86 % 1012 mb 0.17 mm/h
Sun Jan 26 9:00 pm
weather icon
5° | 7°°C 0.9 mm 90% 13 mph 89 % 1011 mb 0 mm/h
Today 12:00 pm
weather icon
3° | 4°°C 0 mm 0% 3 mph 91 % 1004 mb 0 mm/h
Today 3:00 pm
weather icon
4° | 5°°C 0 mm 0% 3 mph 85 % 1004 mb 0 mm/h
Today 6:00 pm
weather icon
4° | 4°°C 0 mm 0% 4 mph 87 % 1003 mb 0 mm/h
Today 9:00 pm
weather icon
3° | 3°°C 0 mm 0% 4 mph 89 % 1004 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 3°°C 0 mm 0% 5 mph 88 % 1004 mb 0 mm/h
Tomorrow 3:00 am
weather icon
2° | 2°°C 0 mm 0% 6 mph 89 % 1005 mb 0 mm/h
Tomorrow 6:00 am
weather icon
2° | 2°°C 0 mm 0% 6 mph 91 % 1005 mb 0 mm/h
Tomorrow 9:00 am
weather icon
4° | 4°°C 0 mm 0% 9 mph 90 % 1003 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,522.14
2.04%
Ethereum(ETH)
€3,161.01
0.44%
XRP(XRP)
€3.02
2.15%
Tether(USDT)
€0.96
0.10%
Solana(SOL)
€243.36
6.45%
Dogecoin(DOGE)
€0.348680
5.71%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000019
1.39%
Pepe(PEPE)
€0.000015
3.61%
Peanut the Squirrel(PNUT)
€0.352001
0.68%
Scroll to Top