Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare reported that hackers accessed internal systems in November 2023 using credentials left active after an earlier Okta incident. The company said it believed the intrusion was a nation-state operation, but it did not publicly identify a government or confirm the actor’s identity. Cloudflare said customer data and systems were not affected. A separate 2025 Salesloft Drift breach exposed text from Salesforce support cases and should not be confused with the 2023 intrusion.

What happened in Cloudflare’s November 2023 breach?

Cloudflare said it detected a threat actor on its self-hosted Atlassian server on November 23, 2023. The investigation found access to Confluence, its internal wiki, and Jira, its bug database, followed by access to Bitbucket, its source-code management system. The actor also tried, unsuccessfully, to reach a console server for a São Paulo data center that had not yet entered production.

Cloudflare reported that the intruder accessed some internal documentation and a limited amount of source code. It said the incident did not affect customer data, customer systems, its services, or the configuration of its global network. These findings and impact statements come from Cloudflare’s account of the incident in its 2023 postmortem.

Why the incident was described as a likely nation-state operation

Cloudflare’s postmortem, authored by Matthew Prince, John Graham-Cumming, and Grant Bourzikas, says: “Based on our collaboration with colleagues in the industry and government, we believe that this attack was performed by a nation state attacker with the goal of obtaining persistent and widespread access to Cloudflare’s global network.” The wording matters: this is Cloudflare’s qualified assessment, not a conclusive public identification of a government or a named attacker.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

How the actor got in

Cloudflare traced access to one access token and three service-account credentials obtained after the October 2023 Okta compromise. Those credentials had not been rotated, leaving them usable. The episode illustrates how credentials connected to a vendor incident can remain a route into another organization when they are not identified and revoked.

Cloudflare’s reported response

Cloudflare said it rotated more than 5,000 production credentials, physically segmented test and staging systems, triaged 4,893 systems, and reimaged and rebooted machines across its global network. That work included systems accessed by the actor and Atlassian products. These are Cloudflare-reported response figures, not independently measured estimates of the breach’s wider prevalence or cost.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

How the separate 2025 Salesloft Drift breach differed

Cloudflare disclosed a different incident after being notified on August 23, 2025, that the Salesloft Drift breach had affected its Salesforce environment. In this event, compromised OAuth credentials associated with the Drift integration enabled access to Salesforce support-case text between August 12 and 17, 2025. Cloudflare’s 2025 postmortem says the exposed records included contact information, case subject lines, and freeform correspondence; attachments and files were not accessed.

Cloudflare warned that customers should treat secrets or credentials pasted into support text as compromised. It reported identifying and rotating 104 Cloudflare API tokens, with no suspicious activity associated with those tokens, and said: “No Cloudflare services or infrastructure were compromised as a result of this breach.” That statement refers to the 2025 Salesloft Drift incident, not the 2023 intrusion. Cloudflare designated the 2025 threat actor GRUB1; that label is not a confirmed identity for the 2023 actor.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Comparison November 2023 intrusion 2025 Salesloft Drift incident
Access path One access token and three service-account credentials retained after the October 2023 Okta compromise Compromised OAuth credentials associated with the Drift integration
Systems reached Internal Atlassian tools: Confluence, Jira, and Bitbucket Salesforce support cases
Data involved Some internal documentation and a limited amount of source code Support-case text, including contact information, subject lines, and correspondence; not attachments or files
Customer impact reported Cloudflare said customer data, systems, services, and global-network configuration were not affected Secrets or credentials pasted into support text could have been exposed; Cloudflare said its services and infrastructure were not compromised
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations can learn from the incidents

The incidents show two distinct ways third-party access can persist: credentials left active after a vendor compromise, and an integration credential used to reach business records. Cloudflare’s 2025 postmortem recommends the following response measures:

  • Disconnect integrations affected by a breach and rotate their credentials.
  • Review support-case text for credentials or secrets, and rotate any that were shared there.
  • Apply least privilege so integrations and service accounts have only the access they need.
  • Monitor for unusual logins and large data exports.

These are Cloudflare’s recommendations, not a guarantee that an organization can prevent every compromise. The credential issue in 2023 also underscores the value of inventorying credentials tied to vendors and promptly revoking or rotating them when those vendors report an incident.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.