Supply chain β›“ Supply Chain

Atlassian Third-Party Breach (February 2023)

πŸ“… 2023-02-01 🏒 Envoy
Primary Source β†—

Incident Details

Atlassian data leak caused by stolen employee credentials. Atlassian has confirmed that a breach at a third-party vendor caused a recent leak of company data and that their network and customer information is secure. 2/17/23: Story and title updated to reflect new statements from both companies. Atlassian suffered a data leak after threat actors used stolen employee credentials to steal data from a third-party vendor. However, the company says its network and customer information are secure. Third-party company: Envoy.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Envoy
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2023-02-01 Breach occurred
  2. 2023-02-16 Publicly disclosed