← Incident database

circleci-2023 · Disclosed 2023-01-04

CircleCI: endpoint malware and stolen SSO session

Endpoint malware stole a two-factor-backed SSO session. Employee privileges enabled access to production stores containing customer variables and credentials.

Endpoint / sessionCredentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Malware stole a valid session cookie.

    [s1]What happened?
  • Reported fact

    The targeted employee could generate production access tokens; the attacker used those privileges.

    [s1]What happened?

Timeline

  1. Investigation dates the endpoint compromise to this day. [s1]

  2. Customer credential rotation alert published. [s2]

Reported response

  • Reported fact

    Endpoint detection and access controls were strengthened; customers were asked to rotate and revoke secrets.

    [s1]Remediation / customer guidance

Evidence relevant to prevention

Operational controls to inspect

MFA does not eliminate stolen-session risk. Inspect endpoint controls and the scope of privileged access.

Editorial assessment; not a determination of liability. [s1][s2]

Unknowns and AI involvement

AI involvementUnknown

The cited primary sources do not establish AI involvement. This does not establish that AI was absent.

This record does not assess all downstream customer impact or individual credential use.

Sources

  1. [s1] CircleCI · Primary source

    CircleCI Jan 4, 2023 security incident report ↗

    Published 2023-01-12 · Reviewed 2026-10-02

  2. [s2] CircleCI · Primary source

    CircleCI security alert: Rotate any secrets ↗

    Published 2023-01-04 · Reviewed 2026-10-02