15 comments

  • htrp 2 days ago

    > As part of our response to this incident, we did our own search through the compromised data to look for tokens or passwords and found 104 Cloudflare API tokens. We have identified no suspicious activity associated with those tokens, but all of these have been rotated in an abundance of caution. All customers whose data was compromised in this breach have been informed directly by Cloudflare.

    Great response

    > We are responsible for the choice of tools we use in support of our business. This breach has let our customers down. For that, we sincerely apologize. The rest of this blog gives a detailed timeline and detailed information on how we investigated this breach.

    And a mea culpa for their 3rd party vendor choices (impressive)

  • Blue923 a day ago

    It would be nice if they actually TOLD us their recommendations with the exact actions to take to protect our accounts. This is just a blanket statement that is going to result in confusion as to what "action" there is to take.

    Does anyone have an action plan yet?

    • loteck a day ago

      From OP:

      Given that Salesforce support case data contains the contents of support tickets with Cloudflare, any information that a customer may have shared with Cloudflare in our support system—including logs, tokens or passwords—should be considered compromised, and we strongly urge you to rotate any credentials that you may have shared with us through this channel.

  • reassess_blind 2 days ago

    Is anyone aware of the other services using Salesloft Drift that were breached? Cloudflare is the first I've had reach out, but surely there were others.

    • bstsb 2 days ago

      so far Google, Zscaler and Palo Alto Networks. looks like more to come though

    • ganoushoreilly 2 days ago

      There were at least 700 victims being tracked by Google's Threat Intelligence Group

  • mr_cyborg 2 days ago

    They saved others, but they couldn’t save themselves.[1]

    Important to remember that security practitioners and vendors are actually on the same team when it comes to criminal behavior, and maybe it’s better to treat others with grace.

    1: https://blog.cloudflare.com/how-cloudflare-mitigated-yet-ano...

    • Citizen8396 a day ago

      comparing a third-party breach of cloudflare to the zoo that was okta at the time is laughable

  • pjsg 2 days ago

    I got this notification (email subject "[ACTION REQUIRED] Third-Party Compromise Impacting Cloudflare Salesforce Cases"), but, as I'm a free user, I don't even have a 'Technical Support' option under the 'Support' menu dropdown.

    Have other free users also received this email?

    • reassess_blind 2 days ago

      Click the Support Dropdown > Support > Technical Support > My Activities

    • bstsb 2 days ago

      if you've ever submitted a support case to Cloudflare then you got the email.

      check https://dash.cloudflare.com/?to=/:account/my-activities

      • pjsg 2 days ago

        That leads to a page saying "Cannot locate dashboard account"

        I did find an email from Cloudflare in April 2011 (seven months after CF started to offer services) which was a response to a support request. I guess that things have changed in the intervening years so that the original link to keep track of my support request no longer works!!

        I'll give them a break on this!

        • TheNewsIsHere 2 days ago

          I’m not giving them a break on this. They sent me the same email. I’m having the same experience.

          I actually do have a support case history with them, and I’d like to review what data has been lost. I’ve been a customer for over a decade. I have no clue what was in that history because I’ve filed numerous tickets over the years. They have made that impossible without paying them, even if you’ve paid them in the past.

          They clearly failed to test their process on each account type.

          I guess we could send individual data subject requests to their DPO, but that is probably more costly for them.

          • luke2030 2 days ago

            Consider if your support cases were instead with Zendesk and not with Salesforce. This could explain why they did not contact you.

            • TheNewsIsHere a day ago

              They did indeed contact me by email to let me know my data was in scope of the breach.