Cloudflare Mitigates Okta Compromise and Introduces HAR Sanitizer Tool

Cloudflare Mitigates Okta Compromise and Introduces HAR Sanitizer Tool

First seen 16 May 2026, 16:51 UTC Cloudflare.Tvblog.cloudflare.com 76% similarity 54.9

Article Content

Browse articles
ThreatCluster

On October 18, 2023, Cloudflare detected an attack originating from a compromised authentication token at Okta. The attackers accessed Cloudflare's Okta instance using session tokens from support tickets, but no customer data was impacted due to rapid response from Cloudflare's Security Incident Response Team (SIRT). This incident marks the second breach linked to Okta, following a previous incident in March 2022. In response, Cloudflare has launched a HAR Sanitizer tool to secure the sharing of HTTP Archive files, which can contain sensitive information. The tool is available for free to all organizations, not just Cloudflare customers. Okta has acknowledged the breach and is urged to improve its security measures to prevent future incidents.

Key Points: • Cloudflare's SIRT detected an attack from a compromised Okta authentication token. • No customer data was impacted due to Cloudflare's rapid incident response. • Cloudflare released a free HAR Sanitizer tool to enhance security for HAR file sharing.

ThreatCluster AI

Timeline

2022-03-01
Previous Okta breach incident
Cloudflare reported a prior incident where Okta's breach did not impact its systems due to effective security measures.
Article 2
2023-10-18
Cloudflare detects attack from Okta breach
Attackers leveraged a compromised authentication token from Okta to access Cloudflare's systems, but no customer data was affected.
Article 2
2023-10-18
HAR Sanitizer tool launched
Cloudflare introduced a HAR Sanitizer tool to secure the sharing of HTTP Archive files, available for free to all organizations.
Article 1

Community

Browse all →