TL;DR: Cloudflare’s breach shows how one missed access token and three service accounts, after the October 2023 Okta incident, enabled lateral movement into Confluence, Jira, and Bitbucket and forced a long secret-rotation campaign, according to Oasis Security. The lesson is that NHI governance fails when inventory, ownership, and rotation speed cannot keep pace with exposed credentials.
At a glance
What this is: This is a breach analysis of Cloudflare’s 2023 incident, where one missed token and three service accounts outlived the response to the Okta breach and were later used to move into internal systems.
Why it matters: It matters because IAM and NHI programmes often assume exposed credentials can be found and rotated before they are abused, yet this case shows how inventory gaps and operational complexity can break that assumption.
By the numbers:
- Cloudflare had to rotate more than 5000 secrets during the incident response effort.
Context
Cloudflare’s breach exposed a familiar NHI governance failure: credentials that were believed to be unused were still live, still trusted and still reachable after a prior compromise. In identity terms, the problem was not just exposure, but the inability to prove which machine credentials existed, where they were used and how quickly they could be withdrawn.
For NHI programmes, this is the difference between knowing a secret is at risk and being able to remove that risk before it is exploited. The case also shows that service accounts and access tokens need the same lifecycle ownership discipline as human accounts, because attacker value comes from persistence, not from the label attached to the identity.
The Cloudflare incident is atypical in scale, but typical in structure: missed inventory, delayed rotation and overconfident assumptions about unused credentials.
Key questions
Q: What breaks when idle NHI secrets are not rotated or revoked?
A: When idle secrets are not rotated or revoked, the organisation loses the distinction between active and abandoned access. A still-valid API key or service account can remain usable long after the workload changed, which lets attackers authenticate quietly and persist without triggering the human login signals many teams monitor.
Q: Why do service accounts with standing privilege create such high breach risk?
A: Because a stolen or leaked machine credential often has direct access to production systems, support tools, or data stores without extra user prompts. If the permission set is broader than the workload needs, the attacker inherits that excess reach. Standing privilege turns one secret into a reusable access path across the environment.
Q: How do you know if NHI secret rotation is actually working?
A: Look for fewer unowned secrets, shorter exposure windows, and successful validation after each change. If rotation regularly causes service failures or leaves old credentials active in side systems, the process is not working as a lifecycle control. Effective rotation reduces risk without creating recurring operational exceptions.
Q: How should teams decide which NHI secrets to revoke first after a breach?
A: Prioritise the identities that combine exposure, privileged reach and uncertain ownership. In practice, that means tokens and service accounts tied to collaboration, source control or build systems should move ahead of low-value credentials because they expand the attacker's options most quickly.
Technical breakdown
How exposed NHI secrets become an internal foothold
The attack began with administrative access to Okta and then shifted to the NHI layer when a token and three service accounts were not rotated. That matters because non-human identities often authenticate quietly, without interactive sign-in prompts or user review, so once a credential survives a response effort it can remain a usable foothold. In this case, the identities were treated as unused, which created a false sense of closure around the initial breach. The operational issue is not only exposure, but the persistence of trust after exposure has been discovered.
Practical implication: inventory exposed NHI credentials as active attack surface, not as cleanup items.
Why secret rotation becomes a race against lateral movement
Secret rotation is not a single action but a dependency exercise. Each credential may support multiple systems, and revoking it without understanding that dependency graph can break production. Cloudflare’s response had to account for Confluence, Jira, Bitbucket and other connected systems, which is why the article emphasizes complexity and timing. NHI identities amplify this problem because they are everywhere, often privileged, and rarely governed by the same user-centric workflows used for humans. The security gap is the delay between detection and safe revocation.
Practical implication: map dependent systems before rotating NHI secrets during incident response.
What standing privilege changes in NHI breach paths
Non-human identities often hold standing privileges because they are built for service continuity, not user convenience. That design makes them attractive for supply chain attacks and lateral movement once a credential is captured or missed during rotation. Unlike human access, these identities usually lack MFA and may be reused across environments, which increases the blast radius when one secret survives. The article’s Cloudflare example shows how a single missed token can become a bridge into internal collaboration and source-code systems.
Practical implication: reduce standing privilege and prohibit reuse across NHI-bound systems.
Threat narrative
Attacker objective: The attacker’s objective was to retain usable credentials long enough to move laterally into internal systems and extend access beyond the initial Okta compromise.
- Entry occurred through the October 2023 Okta compromise, where the attacker gained administrative access and initial trust into the environment.
- Credential access followed when one access token and three service accounts were missed during rotation and remained valid after the response effort.
- Escalation and lateral movement occurred when those identities were used to reach Cloudflare’s Confluence, Jira and Bitbucket systems.
- Impact was a prolonged investigation and a large-scale secret rotation campaign across production and testing environments.
Breaches seen in the wild
- Cloudflare Thanksgiving breach 2023: One service token and three service accounts left unrotated after the Okta breach gave a nation-state attacker access to Cloudflare's Atlassian systems.
- MongoBleed breach: MongoBleed exposed secrets across 87K MongoDB servers.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Unrotated NHI secrets create a trust window that outlives the incident response window: This breach worked because the organisation assumed exposed credentials could be retired before they were weaponised. That assumption failed because service accounts and tokens remained valid after the Okta compromise, turning cleanup delay into attacker opportunity. The practical conclusion is that the risk is not just exposure, but the duration of survivable trust.
Inventory accuracy is the real control boundary for NHI governance: The Cloudflare case shows that a credential believed to be unused can still be live, reachable and privileged. When teams cannot prove where a secret is used, they cannot safely decide when it can be revoked. That makes inventory completeness a governance control, not a documentation exercise.
Secret rotation is an identity lifecycle problem, not a one-off remediation task: Rotating more than 5,000 secrets is an operational event because the attack surface is distributed across systems, environments and owners. The lesson is that lifecycle ownership for NHIs has to include discovery, dependency mapping, revocation and decommissioning, or rotation will always arrive too late.
Standing privilege amplifies the blast radius of every missed credential: NHI credentials are often designed for continuity, which means they remain useful after a compromise unless explicitly withdrawn. That is why overprivileged machine access turns a single missed token into a multi-system breach path. Practitioners should treat privilege scope as part of the rotation decision, not as a separate afterthought.
Ephemeral-credential trust debt: This breach illustrates how organisations accumulate risk when they rely on credentials that are operationally hard to trace, slow to rotate and easy to forget. The debt is paid when attackers find the gap first. The implication for NHI governance is that lifecycle controls must be provable, not merely intended.
From our research library:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to the Ultimate Guide to NHIs.
- Read next: Secrets Management Buyer's Guide
What this signals
Cloudflare-style breaches expose the gap between discovery and defensible revocation: Secret rotation only works when teams can prove which identities exist, where they are used and who owns them. In practice, the control boundary sits at dependency visibility, not at the act of clicking revoke. That is why NHI programmes need lifecycle governance as much as they need secret scanning.
Service accounts behave like high-trust infrastructure, not disposable credentials: When a machine identity can reach collaboration and source-control platforms, its compromise becomes a governance problem across development and operations. Teams should align NHI review cycles with actual access paths, because the attacker will follow the path of least resistance, not the organisational chart.
For practitioners
- Audit exposed NHI credentials immediately Build an incident-time inventory of every token, service account and secret that was touched by the compromise, including identities assumed to be unused.
- Map dependency chains before rotating Document which applications, collaboration tools and build systems depend on each secret so revocation does not interrupt production services.
- Assign explicit ownership for every service account Require a named owner and a decommission date for each non-human identity so no credential is left in a default state of indefinite trust.
- Separate standing privilege from critical workflows Reduce the number of NHI identities that can reach collaboration and source-code systems with persistent access, especially where rotation delays would extend exposure.
- Treat rotation speed as a containment control Measure how quickly exposed machine credentials can be revoked, validated and replaced during an incident, not just whether rotation exists on paper.
Key takeaways
- The breach shows that a missed token or service account can remain dangerous long after the triggering incident has been recognised.
- Cloudflare’s response required rotating more than 5,000 secrets, which illustrates how quickly exposed machine identities can create operational burden.
- The control that matters most is not secret discovery alone, but the ability to revoke, replace and verify machine credentials without losing sight of dependencies.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Missed tokens and service accounts remained active after the incident response began. |
| NHI-05 — Overprivileged NHI | The article shows how privileged service accounts amplified lateral movement after exposure. | |
| NHI-07 — Long-Lived Secrets | Unrotated secrets were still usable after the Okta incident, which is the core failure mode here. | |
| Recommendation — Track exposed credentials to NHI-01 and decommission identities that are no longer needed. Apply NHI-05 to reduce access scope before a leaked secret can be reused. Use NHI-07 to shorten secret lifetime and eliminate credentials that survive breach response. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The breach progressed through retained credentials into internal systems, matching attacker credential and movement tactics. |
| Recommendation — Map the incident to TA0006 and TA0008 to prioritise controls that cut off reused credentials. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The incident reveals a failure to verify and narrow machine access before the credentials were reused. |
| Recommendation — Use PR.AA-05 to review and constrain machine entitlements that survive exposure. | ||
Key terms
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Secrets Rotation: Secrets rotation is the practice of replacing credentials on a schedule or after an event so exposed values stop working quickly. In NHI programmes, rotation must be tied to ownership and automation, otherwise credentials remain valid long after teams believe the risk has been addressed.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Lateral Movement: A post-compromise technique where an attacker uses a compromised NHI to move through a network, accessing additional systems and escalating impact without triggering detection.
Deepen your knowledge
NHI governance, machine identity security, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org