Supply chain
β Supply Chain
Atlassian Third-Party Breach (February 2023)
Primary Source βIncident Details
Atlassian data leak caused by stolen employee credentials. Atlassian has confirmed that a breach at a third-party vendor caused a recent leak of company data and that their network and customer information is secure. 2/17/23: Story and title updated to reflect new statements from both companies. Atlassian suffered a data leak after threat actors used stolen employee credentials to steal data from a third-party vendor. However, the company says its network and customer information are secure. Third-party company: Envoy.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Envoy
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-02-01 Breach occurred
- 2023-02-16 Publicly disclosed