Cloudflare hit by cyberattack
Incident
Summary
Hide ▲
Show ▼
Cloudflare disclosed a Salesforce support-system breach that exposed 104 API tokens and text from customer support cases. The company said attackers accessed its internal case-management instance during August 12-17 after reconnaissance on August 9, then rotated the tokens and alerted customers on September 2. Shared support data such as logs, tokens, or passwords should be treated as compromised, raising follow-on abuse risk.
Related Happenings
UNC6783 BPO compromise campaign targeting downstream companies
Campaign
H score65
First: 09.04.2026 00:46
Last: 09.04.2026 00:46
Sources 1
About this happening:
UNC6783 is an active BPO compromise campaign targeting business process outsourcers and large enterprises to reach downstream environments for extortion. The opera...
UNC6783 BPO compromise campaign targeting downstream companies
CampaignAbout this happening: UNC6783 is an active BPO compromise campaign targeting business process outsourcers and large enterprises to reach downstream environments for extortion. The opera...
OAuth device-code phishing campaign targeting SaaS accounts
Campaign
H score43
First: 04.04.2026 17:17
Last: 04.04.2026 17:17
Sources 1
About this happening:
A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...
OAuth device-code phishing campaign targeting SaaS accounts
CampaignAbout this happening: A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...
Crunchyroll hit by network compromise
Incident
H score69
First: 23.03.2026 21:21
Last: 23.03.2026 21:21
Sources 1
About this happening:
Crunchyroll is investigating a breach that allegedly exposed support systems and user data, putting about 6.8 million people at risk. The claimed intrusion involved a su...
Crunchyroll hit by network compromise
IncidentAbout this happening: Crunchyroll is investigating a breach that allegedly exposed support systems and user data, putting about 6.8 million people at risk. The claimed intrusion involved a su...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon2FA has shifted from a subscription-based PhaaS and AitM credential harvester into a more resilient campaign that now uses device-code phishing against Mic...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon2FA has shifted from a subscription-based PhaaS and AitM credential harvester into a more resilient campaign that now uses device-code phishing against Mic...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
LexisNexis Legal & Professional data leak after AWS intrusion
Data Leak
H score41
First: 03.03.2026 17:40
Last: 03.03.2026 17:40
Sources 1
About this happening:
FulcrumSec leaked 2GB of files tied to LexisNexis Legal & Professional, exposing customer and business information that could be used for follow-on abuse. The company...
LexisNexis Legal & Professional data leak after AWS intrusion
Data LeakAbout this happening: FulcrumSec leaked 2GB of files tied to LexisNexis Legal & Professional, exposing customer and business information that could be used for follow-on abuse. The company...
Timeline
-
02.09.2025 22:54 2 articles · 10mo ago
Initial report: Cloudflare hit by cyberattack
Initial DisclosureAttackers conducted reconnaissance on August 9 and then extracted text from Cloudflare's Salesforce case objects between August 12 and August 17. That early access stage enabled theft of support-ticket content and API tokens.
Show sources
- Cloudflare hit by data breach in Salesloft Drift supply chain attack — www.bleepingcomputer.com — 02.09.2025 22:54
- Blast Radius of Salesloft Drift Attacks Remains Uncertain — www.darkreading.com — 04.09.2025 19:52