On December 7, 2022 (UTC), Atlassian's security team opened an investigation into unauthorized access of a customer's Cloud account. On December 8, we concluded that the bad actor used session tokens, stolen by a piece of malicious software on the customer's computer, to facilitate this access. We promptly invalidated the customer’s affected session tokens. This incident was in no way caused by a vulnerability in Atlassian products or a compromise of Atlassian systems.
Are my session tokens at risk?
Our security team did not find a vulnerability in Atlassian Cloud or On-Premise products or a breach of Atlassian systems related to the incident.
We understand that this incident has spurred many of you to look into the availability of your data on similar dark web marketplaces. We want to emphasize that this was an isolated customer incident caused by malware on the customer’s computer.
Cybercriminals deploy malware as a means to obtain session token data, regardless of cloud or on-premise deployment. If you have any concerns about the security of your account, we recommend that Cloud customers reset their passwords, which will automatically log users out of all active and current sessions. Cloud customers can reset their passwords here: https://id.atlassian.com/manage-profile/security. Server and Data Center customers can contact their administrators to reset their passwords.
If you have further questions, please reach out to our team by filing a support ticket: https://support.atlassian.com/contact/#/.
Regards,
Atlassian
---
[Update] December 22: We would like to thank CloudSek for alerting us to this issue. On December 15, based on their research, we simplified the self-service invalidation of tokens following a password change for Cloud users: a separate user logout is no longer required to invalidate the current session token. For further questions, please reach out to your support representative or file a ticket here: https://support.atlassian.com/contact/#/.
Dan Hranj
Senior Manager - Detections and Response
Atlassian
San Francisco, California
8 comments