← Incident database

cloudflare-thanksgiving-2023 · Disclosed 2024-02-01

Cloudflare: credentials missed during rotation

Credentials stolen in the earlier Okta incident were missed during rotation. They enabled access to self-hosted Atlassian systems and source code.

Credentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    One service token and three accounts were not rotated because they were mistakenly thought unused.

    [s1]Credentials not rotated
  • Reported fact

    The self-hosted Atlassian environment was accessed; Cloudflare reported no impact on customer data or its global network.

    [s1]Executive summary

Timeline

  1. Beginning of disclosed reconnaissance and access. [s1]

  2. Intrusion detected. [s1]

  3. Attacker access terminated. [s1]

  4. Investigation published. [s1]

Reported response

  • Reported fact

    Credentials were rotated broadly and access scope investigated.

    [s1]Remediation

Evidence relevant to prevention

Operational controls to inspect

Reconcile all affected credentials against rotation records and evidence that old credentials are revoked.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited primary sources do not establish AI involvement. This does not establish that AI was absent.

Public sources do not expose credential values or the complete internal authorization model.

Sources

  1. [s1] Cloudflare · Primary source

    Thanksgiving 2023 security incident ↗

    Published 2024-02-01 · Reviewed 2026-10-02