Cloudflare Details Second Okta-Related Intrusion
On October 18, 2023, Cloudflare detected attacks on its systems that it traced back to a compromise at Okta. Threat actors leveraged an authentication token stolen from Okta to pivot into Cloudflare’s Okta instance. Cloudflare’s Security Incident Response Team (SIRT) detected the activity in real time and contained it quickly, minimizing impact. The company has verified that no Cloudflare customer information or systems were impacted.
This marks the second time Cloudflare has been caught up in an Okta breach. In a March 2022 incident, Cloudflare concluded that attackers had no access to its systems or data, thanks to its use of hard keys for multi-factor authentication. In this latest case, however, the attacker managed to gain access through an open Okta session with Administrative privileges.
The key to mitigating the incident was early detection. Cloudflare contacted Okta about the breach before Okta had notified them. The company used its own Zero Trust Access, Gateway, Data Loss Prevention, and Cloudforce One threat research to validate the scope and contain the attack before the threat actor could establish persistence on the network.
The Attack Path
According to Okta’s public statement, the threat actor accessed Okta’s customer support system and viewed files uploaded by customers as part of recent support cases. In Cloudflare’s case, the attacker hijacked a session token from a support ticket created by a Cloudflare employee. Using that token, the attacker accessed Cloudflare systems on October 18.
During the incident, Cloudflare observed that threat actors compromised two separate Cloudflare employee accounts within the Okta platform. Cloudflare detected this internally more than 24 hours before Okta notified them of the breach. Cloudflare’s Zero Trust architecture protects its production environment, which helped prevent any customer impact.
Recommendations for Okta
Cloudflare is urging Okta to implement several best practices:
- Take any report of compromise seriously and act immediately; Okta was first notified by BeyondTrust on October 2, 2023, but the attacker still had access to their support systems at least until October 18, 2023.
- Provide timely, responsible disclosures to customers when a breach of their systems affects them.
- Require hardware keys to protect all systems, including third-party support providers.
Recommendations for Okta Customers
For organizations using Okta, Cloudflare advises the following steps:
- Enable hardware MFA for all user accounts. Passwords alone are insufficient; hardware keys are strongly recommended since other MFA methods can be vulnerable to phishing.
- Investigate all unexpected password and MFA changes, suspicious support-initiated events, and ensure all password resets are valid. Force a password reset for any account under suspicion.
- Monitor for new Okta users, reactivation of existing users, sessions lacking proper authentication, account and permission changes, MFA policy overrides or removals, delegation of sensitive applications, and supply chain providers accessing your tenants.
- Review session expiration policies to limit session hijack attacks.
- Utilize tools like Cloudflare Access Device Posture Check to validate devices connected to critical systems.
- Practice defense in depth for detection and monitoring strategies.
Cloudflare’s Security and IT teams continue to monitor the situation. The company has stated it will publish updates if further information is disclosed by Okta or discovered through additional log analysis.



