circleci-2023 · Disclosed 2023-01-04
CircleCI: endpoint malware and stolen SSO session
Endpoint malware stole a two-factor-backed SSO session. Employee privileges enabled access to production stores containing customer variables and credentials.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
Endpoint detection and access controls were strengthened; customers were asked to rotate and revoke secrets.
[s1]Remediation / customer guidance
Evidence relevant to prevention
Operational controls to inspect
MFA does not eliminate stolen-session risk. Inspect endpoint controls and the scope of privileged access.
Editorial assessment; not a determination of liability. [s1][s2]
Unknowns and AI involvement
The cited primary sources do not establish AI involvement. This does not establish that AI was absent.
This record does not assess all downstream customer impact or individual credential use.
Sources
[s1] CircleCI · Primary source
CircleCI Jan 4, 2023 security incident report ↗Published 2023-01-12 · Reviewed 2026-10-02
[s2] CircleCI · Primary source
CircleCI security alert: Rotate any secrets ↗Published 2023-01-04 · Reviewed 2026-10-02