Cloudflare says it was almost fooled by a phishing attack


Cloudflare employees were recently targeted by a “sophisticated” cyberattack, and even though some fell for the scheme, the DDoS protection company managed to successfully defend itself.
In a blog post (opens in new tab), Cloudflare co-founder Matthew Prince, together with team members Daniel Stinson-Diess and Sourov Zaman, explained how the attack happened and what made the difference between success and failure.
The threat actor made a couple of key preparations ahead of the attack: they registered a domain that looked legitimate and would fool many victims: cloudflare-okta.com. Okta is Cloudflare’s identity provider. They also managed to somehow obtain the phone numbers of almost 80 Cloudflare employees, as well as family members for some.
Time-based passcodes vs security keys
After the attack, Cloudflare sought to understand how the threat actors obtained these phone numbers but came up empty given that access logs to employee directories showed no signs of compromise.
Then, they created a phishing page that looks identical to the genuine Okta login page and hosted it on DigitalOcean. They also set the page up in such a way that the login credentials submitted would be sent, in real-time, via Telegram, to the attackers. That way, the crooks would be able to submit them to the actual Okta login page right away and have enough time to obtain any two-factor authentication from the victims, as well.
Once all the preparations were done, they sent out an SMS message to everyone, saying “Alert! Cloudflare schedule has been updated”, and provided a link.
While most employees did not fall for the trick, some did. However, Cloudflare’s additional security measures ensured that the attackers never got access to its systems. The company does not use Time-based One Time Passcode (TOTP), but instead relies on FIDO2-compliant security keys.
“Since the hard keys are tied to users and implement origin binding, even a sophisticated, real-time phishing operation like this cannot gather the information necessary to log in to any of our systems,” the authors explained. “While the attacker attempted to log in to our systems with the compromised username and password credentials, they could not get past the hard key requirement.”
It seems as Cloudflare dodged this bullet, but it says that due to the sophistication of the attack, many other victims might not. Those that fell for the trick, probably ended up with AnyDesk’s remote access software installed on the endpoints (opens in new tab). “That software, if installed, would allow an attacker to control the victim’s machine remotely,” the company concluded.
The attack comes shortly after Twilio also revealed it was hit by a similar phishing attack, where hackers tricked company employees into giving away their login credentials which were then used to sneak into the company network, map out the endpoints, and steal even more data.
Audio player loading… Cloudflare employees were recently targeted by a “sophisticated” cyberattack, and even though some fell for the scheme, the DDoS protection company managed to successfully defend itself. In a blog post (opens in new tab), Cloudflare co-founder Matthew Prince, together with team members Daniel Stinson-Diess and Sourov Zaman,…
Recent Posts
- Your new favorite teacher might be this AI educator that never loses their patience
- Kia’s next EV is the affordable, long-range EV4 sedan
- Meta’s AI chatbot will soon have a standalone app
- Framework’s Laptop 12 Could Inject New Life Into Budget Portable PCs
- CRKD teamed up with Gibson to make new guitar controllers
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010