Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Cloudflare Thanksgiving Breach 2023: How Four Credentials Left…
Breach analysis Incident: 14 Nov 2023

Cloudflare Thanksgiving Breach 2023: How Four Credentials Left Unrotated After the Okta Breach Let a Nation-State Attacker In

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
Category: NHI
On this page

On Thanksgiving Day, 23 November 2023, Cloudflare detected an attacker on its self-hosted Atlassian server. The attacker had got in with credentials taken in the October 2023 Okta support system breach: one service token and three service account credentials that Cloudflare had meant to rotate but had not, because it wrongly believed they were unused. They were a Moveworks service token with remote access to Cloudflare's Atlassian system, a Smartsheet service account with administrative access to Jira, a Bitbucket service account used to access source code, and an AWS environment with no access to the global network or customer data. From 14 November the attacker explored Cloudflare's Confluence wiki and Jira bug database, established persistence with ScriptRunner for Jira, viewed 120 of almost 12,000 code repositories and tried, without success, to reach a console server in a new São Paulo data centre. Cloudflare cut off access on 24 November, said no customer data or systems were affected and attributed the attack to a likely nation-state actor. It then rotated more than 5,000 production credentials.

Key takeaways

  • The attacker used one service token and three service account credentials stolen in the October 2023 Okta breach that Cloudflare had failed to rotate.
  • Cloudflare kept them because it mistakenly believed they were unused.
  • With a Smartsheet service account's Jira admin rights, the attacker installed the Sliver framework through ScriptRunner for Jira to keep access.
  • The attacker viewed 120 code repositories, 76 of which Cloudflare believes were downloaded, and was removed on 24 November 2023.
  • The identity lesson: after a breach, rotate every exposed credential, because "unused" is a guess until it is verified.

At a glance

OrganisationCloudflare (content delivery and security provider)
When14 to 24 November 2023; disclosed 1 February 2024
AttackerLikely a nation-state actor, according to Cloudflare
Entry pointCredentials stolen in the October 2023 Okta support system breach and not rotated
Identities abusedA Moveworks service token; Smartsheet and Bitbucket service accounts; an AWS environment credential
ImpactAccess to Confluence, Jira and Bitbucket; 120 repositories viewed; no customer data or systems affected
CategoryNHI. Incident class: confirmed NHI breach (unrotated service token and service accounts)

What happened

Cloudflare was one of the customers hit by the October 2023 Okta breach, when an attacker used a session token taken from Okta's support system to access Cloudflare's Okta instance. Cloudflare said it then set out to rotate the credentials exposed, but "we failed to rotate one service token and three service accounts (out of thousands) of credentials that were leaked during the Okta compromise." It explained: "The one service token and three accounts were not rotated because mistakenly it was believed they were unused. This was incorrect and was how the threat actor first got into our systems and gained persistence to our Atlassian products."

The attacker began using those credentials in mid-November. According to Cloudflare, "From November 14 to 17, a threat actor did reconnaissance and then accessed our internal wiki (which uses Atlassian Confluence) and our bug database (Atlassian Jira)." The attacker returned on 22 November and "established persistent access to our Atlassian server using ScriptRunner for Jira, gained access to our source code management system (which uses Atlassian Bitbucket), and tried, unsuccessfully, to access a console server that had access to the data center that Cloudflare had not yet put into production in São Paulo, Brazil." The Register reported that the Smartsheet service account's admin access let the attacker install the Sliver Adversary Emulation Framework, and that the attacker searched the wiki for information about remote access, secrets and tokens and viewed 120 of almost 12,000 repositories, 76 of which Cloudflare treated as exfiltrated.

Cloudflare detected the attacker on 23 November and cut off access on 24 November; CrowdStrike later confirmed the last activity was that morning. Cloudflare said it believed the attack "was performed by a nation state attacker with the goal of obtaining persistent and widespread access to Cloudflare's global network." In a remediation project it called Code Red, it rotated every production credential, more than 5,000 in total, triaged 4,893 systems and reimaged every machine in its global network. BleepingComputer reported that Cloudflare said no customer data or systems were affected.

Timeline

DateEvent
18 October 2023Cloudflare's Okta instance is accessed with a token stolen from Okta's support system.
14 to 17 November 2023Attacker probes Cloudflare and accesses Confluence and Jira with unrotated credentials.
22 November 2023Attacker establishes persistence via ScriptRunner for Jira and accesses Bitbucket.
23 November 2023Cloudflare detects the attacker.
24 November 2023All attacker access is terminated.
27 November 2023 to 5 January 2024Code Red remediation, including rotation of more than 5,000 credentials.
1 February 2024Cloudflare publishes details of the incident.

How it happened: the identity attack path

  1. Credentials exposed upstream. The Okta support system breach leaked Cloudflare credentials.
  2. Rotation gap. Cloudflare rotated thousands of credentials but skipped four it thought were unused.
  3. Service identities reused. The attacker used a Moveworks service token and Smartsheet and Bitbucket service accounts.
  4. Persistence. Admin rights in Jira allowed installation of the Sliver framework through ScriptRunner.
  5. Discovery and eviction. Cloudflare detected the attacker on 23 November and removed them the next day.

Impact

  • Accessed: Confluence wiki pages, 36 Jira tickets and 120 code repositories, 76 of them treated as exfiltrated.
  • Not affected: customer data, services, global network systems and configuration, according to Cloudflare.
  • Response: more than 5,000 production credentials rotated and every machine in the global network reimaged.

What this means for NHI governance

This is one of the clearest examples of a second breach caused by incomplete rotation after a first. Cloudflare did the hard part, rotating thousands of credentials, and was caught by four that nobody believed were in use. Integration credentials such as Moveworks and Smartsheet service accounts are easy to forget because no person logs in with them, yet one of them held admin rights over Jira.

The fix is a reliable inventory with usage data, so that "unused" is a fact, not a belief, and a rotation plan that covers every exposed credential regardless. See our Leaked Credential Response Playbook and Service Account Security Guide.

Recommendations

  • Rotate every exposed credential. After a breach, do not exempt credentials believed to be unused. See our Leaked Credential Response Playbook.
  • Keep an inventory with last-used data. Retire credentials that are genuinely unused instead of leaving them valid. See the NHI Ownership Guide.
  • Limit integration privileges. A SaaS integration rarely needs admin rights over Jira. See the SaaS and OAuth App Governance Guide.
  • Monitor service accounts for new behaviour. Plugin installs and bulk repository access by a service account are red flags. See the ITDR Guide.
  • Remove HAR files and secrets from wikis. Cloudflare deleted HAR files uploaded to its wiki in case they held tokens. See the Secrets Management Guide.

Frequently asked questions

How was Cloudflare breached in November 2023?

The attacker used one service token and three service account credentials stolen in the October 2023 Okta breach that Cloudflare had not rotated.

Why were the credentials not rotated?

Cloudflare said it mistakenly believed they were unused.

Was Cloudflare customer data affected?

No. Cloudflare said no customer data or systems were affected and that the attacker's access was limited to its Atlassian environment.

Okta Support System Breach 2023 · Salesloft Drift Breach 2025 · Leaked Credential Response Playbook · Service Account Security Guide · SaaS and OAuth App Governance Guide

How NHI Mgmt Group can help

A rotation plan is only as good as the inventory behind it. We help teams find every integration credential, verify what is in use and rotate completely after an incident. See our NHI and AI agent security training.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org