
8/9/2022 · Matthew Prince, Daniel Stinson-Diess, Sourov Zaman
What this post added
This post details a sophisticated phishing attack targeting Cloudflare employees, including the mechanics of the attack (SMS phishing, fake Okta login page, real-time TOTP relay) and Cloudflare's response. It highlights the effectiveness of FIDO2 security keys in preventing compromise despite credential leakage, and the use of Cloudflare Gateway to block malicious domains. The post also outlines steps taken to identify and take down attacker infrastructure, update detections, and audit logs. Lessons learned include enhancing access controls for newly registered domains, implementing browser isolation for suspicious sites, and leveraging Area 1's phish-identification technology.