Cloudflare was breached by suspected government spies who gained access to their internal Atlassian installation using stolen credentials from a security breach at Okta.
Cloudflare failed to rotate the stolen tokens because they incorrectly believed they were unused, allowing the intruders to access their Atlassian system and other systems.