Ransomware attack

Matthew Furry June 5, 2022

We were too slow to patch (and don't have maintenance) and our Confluence on-prem is now locked up.  I've stopped the thread that was encrypting, but it looks like backups were deleted and attachments encrypted.  

Any experiences so far in the community?

4 answers

1 vote
Mayur Jadhav
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
June 5, 2022

I think multiple instances got affected by this vulnerability, some observations are like, home directory is missing, couple of files are locked, random users were created with Admin privileges. 

0 votes
Mayur Jadhav
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
June 8, 2022

Hi Santosh,

It would be good if you have the backup, would suggest to to create new instance and restore the backup. May be they downloaded not sure about this. Atlassian is trying to mitigate the problem. 

0 votes
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 8, 2022

@Mayur Jadhav Do you think there is a home folder download? or it is just remote code execution to prevent use of confluence server?

0 votes
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 5, 2022

I have faced the same issue here.. not sure if the whole home folder got downloaded by the hacker...I keep taking weekly backups and found not much data loss for me so far.. 

Suggest an answer

Log in or Sign up to answer
AUG Leaders

Atlassian Community Events