A suspected nation-state actor used credentials exposed in the October 2023 Okta incident to enter Cloudflare’s internal Atlassian environment the following month. The credentials Cloudflare said were used were one access token and three service-account credentials that had not been rotated. The actor reached Confluence, Jira and Bitbucket, but Cloudflare reported no impact to customer data, services, its global network or network configuration.
How the Okta incident led to the Cloudflare intrusion
Cloudflare said its Okta instance was breached on October 18, 2023, using an authentication token stolen from Okta’s support system. The later Cloudflare intrusion was enabled by credentials exposed through that incident and left usable: one access token and three service-account credentials. Cloudflare had not rotated those four credentials.
The connection was therefore a credential-lifecycle failure after a third-party breach. Access to Okta was not the same event as access to Cloudflare’s Atlassian server, but the earlier compromise exposed credentials that the attacker could later use against Cloudflare.
| Date | What Cloudflare reported |
|---|---|
| October 18, 2023 | Cloudflare’s Okta instance was breached using an authentication token stolen from Okta’s support system. |
| November 14, 2023 | The actor first accessed Cloudflare’s self-hosted Atlassian server. |
| November 22, 2023 | The actor returned, established persistence and reached Bitbucket. |
| November 23, 2023 | Cloudflare detected the activity. |
| Morning of November 24, 2023 | Cloudflare severed the actor’s access. |
These dates and the credential details come from Cloudflare’s incident disclosure, reproduced in Telelink/ASOC’s March 2024 security bulletin.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Which Cloudflare systems and information the actor accessed
The actor accessed Cloudflare’s self-hosted Atlassian systems: Confluence, Jira and Bitbucket. Cloudflare said the actor searched documentation, bug records and source repositories for information about the architecture, security and management of its global network.
The actor also attempted to reach a console for a São Paulo data center that was not yet in production. That route failed. The public account does not establish that the actor accessed production network systems or changed their configuration.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Cloudflare’s executives described the access as limited, saying the actor reached “some documentation and a limited amount of source code.” This was an intrusion into internal collaboration and development systems, not a reported breach of Cloudflare’s customer-facing services.
What Cloudflare said about customer and production impact
Cloudflare reported no impact to customer data, services, its global network or network configuration. That is the company’s account of the incident; it should not be expanded into a claim that no internal information was accessed. Cloudflare confirmed access to documentation and a limited amount of source code.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Cloudflare’s CEO Matthew Prince, CTO John Graham-Cumming and CISO Grant Bourzikas said they believed the attack was carried out by a nation-state actor seeking “persistent and widespread access to Cloudflare’s global network.” The public account supports describing the perpetrator as a suspected nation-state actor. It does not name a country, intelligence service or specific group, and it does not establish a government identity as proven.
How Cloudflare responded
Cloudflare said it rotated more than 5,000 production credentials and performed forensic triage on 4,893 systems. It also physically segmented test and staging systems and reimaged or rebooted affected systems. These figures describe Cloudflare’s response to this incident, not a general estimate of how many systems or credentials another organization would need to handle.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The response illustrates why containment after a third-party compromise cannot stop at changing employee passwords. Exposed access tokens, service accounts and other machine credentials can remain usable even if the original vendor incident is contained. An organization needs an inventory broad enough to find credentials that are not tied to an individual user, then must revoke and reissue those credentials and check for related unauthorized access.
How to keep exposed credentials from enabling a second breach
- Identify the exposure window and affected systems. Establish which identity-provider tenants, applications, administrators and integrations could have been reached during the vendor incident. Use the vendor’s incident updates alongside your own authentication and application logs.
- Inventory credentials, including nonhuman ones. Find access tokens, service-account credentials, API credentials and other machine-to-machine secrets associated with the affected systems. Record their owners, permissions and dependent services so rotation does not leave unknown credentials active.
- Revoke and replace exposed credentials. Do not assume an exposed credential is safe because it has not yet appeared in an alert. Revoke it, issue a replacement through the normal controlled process, and confirm dependent integrations work with the new credential.
- Invalidate active sessions and review access. Credential rotation and session invalidation address different risks. Review active sessions and authentication records for suspicious use, and terminate sessions that may have been established by an attacker.
- Limit what accounts and tokens can reach. Use least privilege, restrict administrative actions and network access where feasible, and avoid long-lived credentials when a shorter-lived or more narrowly scoped option is available.
- Verify containment across connected environments. Review application, source-control, identity and cloud audit records, including test and staging environments. Reimage or rebuild affected systems when forensic findings warrant it, rather than relying only on a password change.
Okta’s February 8, 2024 closure notice said Stroz Friedberg found no further malicious activity beyond the previously determined October 2023 incident. Okta listed follow-up controls including zero-standing administrator privileges, step-up MFA for protected administrative actions, IP binding, anonymizer blocking and allowlisted API network zones. Those measures concern identity and access controls; they do not remove the need for customers to rotate credentials that may already have been exposed.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Why MFA alone may not stop session-token theft
Multifactor authentication can prevent an attacker from signing in with only a stolen password, but a successful login can create an authenticated browser session. If an attacker steals that session token, the attacker may be able to reuse the session without repeating the login and MFA challenge.
Cloudflare’s March 4, 2026 report on Tycoon 2FA describes this separate, more recent phishing pattern. The kit operated as a reverse proxy: it relayed a victim’s login and MFA in real time, captured the resulting session token, and allowed the attacker to inherit the authenticated browser session. Cloudflare said the kit abused Cloudflare Workers and used anti-analysis redirects to benign sites such as Amazon. This 2026 activity is not the cause of the 2023 Cloudflare intrusion; it illustrates why protecting passwords and requiring MFA are not, by themselves, complete session defenses.
Which defenses address reverse-proxy phishing and stolen sessions
| Control | Where it applies | What it helps address | Important limit |
|---|---|---|---|
| FIDO2/WebAuthn security keys or passkeys | Identity and sign-in | Phishing-resistant authentication; Cloudflare recommends these in response to token-stealing phishing. | They do not replace review and invalidation of sessions that may already have been stolen. |
| Managed-device and conditional-access rules | Identity and endpoint | Restrict access using device-management and access conditions, rather than relying only on a password and MFA prompt. | They require policies that fit the organization’s devices and workflows. |
| Token binding, shorter session lifetimes and continuous access evaluation | Identity and session management | Reduce the usefulness or duration of a stolen session and support reassessing access after sign-in. | Session controls complement phishing-resistant authentication; they do not remove the need to investigate an affected account. |
| DNS filtering and sandboxing | Network and endpoint | Help identify or block malicious destinations and suspicious content involved in phishing. | They are not substitutes for controls on credentials and authenticated sessions. |
| Strict DMARC, SPF and DKIM | Email domain and delivery | Help strengthen defenses against email spoofing and phishing delivery. | Email protections do not invalidate a session token once an attacker has captured one. |
The controls above are among those Cloudflare recommended in its Tycoon 2FA report. They protect different parts of an attack path: authentication, device eligibility, active sessions, network access and email. Their implementation effort and cost depend on an organization’s existing identity, endpoint and email environment; Cloudflare’s report does not provide comparable cost or deployment-time figures.
Quick Recap
What the incident establishes—and what it does not
- Established: Cloudflare said credentials exposed in the October 2023 Okta incident remained unrotated and were used to access its Atlassian environment in November.
- Established: The actor accessed Confluence, Jira and Bitbucket and searched internal documentation, bug records and source repositories.
- Established: Cloudflare reported no impact to customer data, services, global network systems or configuration.
- Not publicly identified: A country, intelligence service or named threat group behind the suspected nation-state activity.
- Not reported as successful: The attempted route to the not-yet-production São Paulo data-center console.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →

