Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

JumpCloud said a North Korean threat actor breached its systems in June 2023 after spear-phishing a software engineer. The company reported that fewer than five customer organizations and fewer than ten devices were affected, and said it notified every impacted customer directly. JumpCloud said its incident-response partner CrowdStrike confirmed the North Korean attribution; the public statements cited here are company reporting, not an independent public government attribution.

How the JumpCloud breach began

According to JumpCloud’s September 2023 account, the intrusion began on June 20, 2023, when a sophisticated North Korean threat actor spear-phished a JumpCloud software engineer. The engineer downloaded malicious code onto a company-issued device, giving the attacker developer-level access to JumpCloud environments.

On June 22, JumpCloud said, the attacker used that access to pivot to other systems and launch workloads in the company’s container orchestration system for later execution. On June 27, the attacker injected instructions into JumpCloud’s commands framework that caused targeted devices to download malware.

JumpCloud breach timeline

Date and time (UTC) What JumpCloud reported
June 20, 2023 A software engineer was spear-phished and downloaded malicious code onto a JumpCloud-issued device.
June 22 The actor used developer-level access to pivot to other systems and launch workloads in the container orchestration environment.
June 23, 02:21 JumpCloud security tools alerted on anomalous activity associated with the compromised employee account. The company said it revoked system access and rotated known affected credentials.
June 27, 15:13 JumpCloud noticed a workload running in its orchestration system. The company said it had no evidence of customer impact at that point.
July 4 JumpCloud said it identified and rebuilt the last impacted system.
July 5, 03:35 The company said it discovered customer impact in its commands framework after finding an anomaly in database records and determining that a June 27 injection had instructed targeted devices to download malware.
July 5, 23:11 JumpCloud said it began force-rotating all administrator API keys.

The company’s public update first described anomalous activity on June 27 and later reported that it discovered customer impact on July 5. Its September 20 update to that post followed the conclusion of the investigation; a more detailed remediation account appeared on September 7.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who JumpCloud blamed, and what the company said was affected

JumpCloud attributed the operation to North Korea and said CrowdStrike confirmed its assessment. That is the attribution JumpCloud reported, not an independent public government finding in the cited statements.

JumpCloud said fewer than five customer organizations and fewer than ten devices were affected, out of more than 200,000 organizations relying on the platform. It did not give exact counts in those statements. It also said all affected customers were notified directly before the public announcement.

What JumpCloud said it did after detecting the intrusion

In its September 7 remediation update, JumpCloud described a response that included:

  • Revoking access and rotating credentials and API keys.
  • Rebuilding affected infrastructure, freezing code deployment during the investigation, and checking source code and binaries.
  • Auditing internal endpoints and expanding monitoring.
  • Reviewing IAM permissions and tightening least-privilege controls.
  • Requiring manual authorization by multiple parties for elevated access, with multi-party authorization for access that could affect customer devices or security.
  • Engaging CrowdStrike for incident response and contacting U.S. federal law enforcement.

JumpCloud said it found no evidence that source code or binary releases were compromised and no further indicators on its systems after July 4. These are the company’s reported findings and remediation actions from 2023; they do not independently establish its current security posture.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In the September 7 update, JumpCloud CISO Bob Phan wrote: “All access to data that could affect customer devices or security directly or indirectly is now multi-party authorized.” This describes the company’s claim at that time.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What JumpCloud customers should do

JumpCloud advised customers to review logs covering June 20 through July 5 against its incident indicators, rotate static credentials supplied to JumpCloud—including SAML certificates, passwords, and integration secrets—and follow its hardening guidance. If responding now, involve your security team and verify the current official guidance before acting; the incident indicators are historical, not a guarantee of current threat coverage.

  1. Review the historical indicators carefully. JumpCloud’s IoC page says the lists were last updated July 14, 2023 at 14:47 UTC, and that the page was updated August 3, 2023.
  2. Apply indicators in security tools rather than contacting them. JumpCloud recommends using the indicators with EDR and perimeter-security solutions and warns against contacting listed IPs or URLs directly from company infrastructure.
  3. Account for false positives and stale indicators. The IoC page warns that attackers may not reuse IP addresses and that IPs can be recycled. Blocking or alerting on old indicators can therefore generate false positives or disrupt legitimate traffic.
  4. Rotate relevant credentials and check access. Prioritize static credentials provided to JumpCloud, and work with your security team to determine what logs and access changes are appropriate for your environment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.