On 22 June 2023, a nation-state actor later identified as North Korean began a spear-phishing campaign against JumpCloud, a cloud directory and device management provider used by more than 200,000 organisations. On 27 June JumpCloud found anomalous activity on an internal orchestration system, rotated credentials and rebuilt infrastructure. The attacker was not gone. On 5 July JumpCloud saw unusual activity in its commands framework, the feature that pushes commands to customers' managed devices, for a small set of customers. It force-rotated every customer's admin API keys that day and later identified the attack vector as "data injection into our commands framework." JumpCloud says fewer than five customers and fewer than ten devices were affected. The incident showed how an identity provider's own infrastructure can become a route into its customers.
Key takeaways
- A spear-phishing campaign that began on 22 June 2023 gave a nation-state actor access to a specific area of JumpCloud's infrastructure, according to JumpCloud.
- The attacker persisted past JumpCloud's first credential rotation and, by 5 July, was injecting data into the commands framework used to run commands on customers' devices.
- JumpCloud force-rotated all customer admin API keys on 5 July 2023, before publicly explaining why.
- JumpCloud and CrowdStrike identified the actor as North Korea; fewer than five customers and fewer than ten devices were impacted.
- The identity lesson: platforms that manage other organisations' identities and devices are high-value targets, and their admin API keys are keys to their customers.
At a glance
| Organisations | JumpCloud; fewer than five of its customers |
|---|---|
| When | Spear-phishing from 22 June 2023; detected 27 June; customer impact found 5 July; disclosed 12 July 2023; attribution update September 2023 |
| Attacker | A North Korean nation-state actor, according to JumpCloud and confirmed by CrowdStrike |
| Entry point | A spear-phishing campaign against JumpCloud, which led to unauthorised access to an internal orchestration system |
| Identities abused | JumpCloud internal credentials (rotated after detection); the commands framework that acts on customers' managed devices; customer admin API keys, force-rotated as a precaution |
| Impact | Malicious data injected into the commands framework for a small, targeted set of customers; fewer than ten devices affected, according to JumpCloud |
| Category | NHI. Incident class: confirmed NHI breach (identity platform infrastructure abused to reach customers) |
What happened
"On June 27 at 15:13 UTC we discovered anomalous activity on an internal orchestration system which we traced back to a sophisticated spear-phishing campaign perpetrated by the threat actor on June 22," JumpCloud's CISO, Bob Phan, wrote. "That activity included unauthorized access to a specific area of our infrastructure. We did not see evidence of customer impact at that time." The company rotated credentials, rebuilt infrastructure, strengthened its perimeter and brought in incident response help and law enforcement.
The investigation continued. "On July 5 at 03:35 UTC, we discovered unusual activity in the commands framework for a small set of customers. At this point in time, we had evidence of customer impact." JumpCloud's commands framework lets administrators run commands on the devices JumpCloud manages. The company decided "to perform a force-rotation of all admin API keys beginning on July 5 at 23:11 UTC" and notified customers; the reason for the reset was only made public a week later, as SecurityWeek noted.
On 12 July JumpCloud published the details. "Continued analysis uncovered the attack vector: data injection into our commands framework. The analysis also confirmed suspicions that the attack was extremely targeted and limited to specific customers." It released indicators of compromise. The Register noted that JumpCloud did not answer questions about what was accessed or who was targeted.
In a September 2023 update, JumpCloud said CrowdStrike was its incident response partner and that "we identified and CrowdStrike confirmed the nation-state actor involved was North Korea. Importantly, fewer than 5 JumpCloud customers were impacted and fewer than 10 devices total were impacted, out of more than 200,000 organizations who rely on the JumpCloud platform."
Timeline
| Date | Event |
|---|---|
| 22 June 2023 | The threat actor begins a spear-phishing campaign against JumpCloud. |
| 27 June 2023 | JumpCloud detects anomalous activity on an internal orchestration system and rotates credentials. |
| 5 July 2023 | Unusual activity in the commands framework affects a small set of customers; JumpCloud force-rotates all admin API keys. |
| 12 July 2023 | JumpCloud publishes incident details and indicators of compromise. |
| September 2023 | JumpCloud attributes the attack to North Korea, confirmed by CrowdStrike, and says fewer than five customers were impacted. |
How it happened: the identity attack path
- Spear-phishing. A targeted phishing campaign against JumpCloud began on 22 June 2023.
- Internal foothold. The actor gained access to a specific area of JumpCloud's infrastructure, including an internal orchestration system.
- Persistence through rotation. Despite credential rotation and rebuilds after 27 June, the actor retained or regained access.
- Abuse of the device command channel. The actor injected data into the commands framework to reach a small set of targeted customers' devices.
- Precautionary key reset. JumpCloud reset every customer's admin API keys to cut off any credential the actor might hold.
Impact
- Confirmed: fewer than five customers and fewer than ten devices impacted, according to JumpCloud.
- Platform-wide: all customer admin API keys force-rotated as a precaution.
- Not disclosed: which customers were targeted, what data was accessed and what the injected commands did.
What this means for NHI governance
JumpCloud sits in the identity layer of its customers: it manages their directories, their devices and the commands those devices run. That makes its internal systems and its customers' admin API keys some of the most powerful machine credentials its customers have, even though they are held by a vendor. An attacker who reaches the command channel can act on customer devices without touching the customers' own defences.
For customers, the lesson is to treat identity and device management vendors as tier-zero suppliers: scope and rotate the API keys you give them, monitor what commands they push, and be ready to rotate quickly when they ask. For providers, persistence after the first rotation is the warning: a first clean-up is not the end. See our Third-Party Access Guide and API Key Management Guide.
Recommendations
- Treat identity and device management vendors as tier-zero. Assess them like your own identity provider and plan for their compromise. See the Third-Party Access Guide.
- Scope and rotate admin API keys. Give integrations the least privilege they need, store keys in a vault and rotate them regularly and on request. See our API Key Management Guide.
- Monitor commands pushed to endpoints. Alert on unusual commands or scripts sent through management platforms.
- Harden staff against spear-phishing. Use phishing-resistant MFA for employees with access to production and orchestration systems. See the MFA Guide.
- Verify eradication after the first clean-up. Keep hunting after initial rotation; persistent actors often keep a way back in. See the ITDR Guide.
Frequently asked questions
What happened in the JumpCloud breach?
A North Korean nation-state actor used spear-phishing to access JumpCloud's infrastructure from 22 June 2023, then injected data into its commands framework to target a small set of customers. JumpCloud force-rotated all customer admin API keys on 5 July.
How many JumpCloud customers were affected?
JumpCloud says fewer than five customers and fewer than ten devices were impacted, out of more than 200,000 organisations using its platform.
Why did JumpCloud reset all API keys?
After finding unusual activity in its commands framework on 5 July 2023, JumpCloud force-rotated all admin API keys as a precaution to cut off any access the attacker might have, before publishing details on 12 July.
Related NHI Mgmt Group resources
Okta Support System Breach 2023 · BeyondTrust Breach 2024 · Third-Party Access Guide · API Key Management Guide · Identity Provider and SSO Security Guide
How NHI Mgmt Group can help
Identity and device management vendors hold some of the most powerful keys in any organisation. We help teams assess those suppliers, scope and rotate the credentials they hold and prepare for a provider-side incident. See our NHI and AI agent security training.