Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io
Cloud Threat Landscape

Rollbar hack

Type
Incident
Actors
❓Unknown
Pub. date
September 13, 2023
Initial access
End-user compromise
Impact
Data exfiltration
Observed techniques
Valid creds abuse
References
https://www.bleepingcomputer.com/news/security/rollbar-discloses-data-breach-after-hackers-stole-access-tokens/https://twitter.com/troyhunt/status/1700531521835454502
Status
Stub
Last edited
Jun 2, 2024 8:02 AM

The security breach was discovered by Rollbar on September 6 when reviewing data warehouse logs showing that a service account was used to log into the cloud-based bug monitoring platform.

Once inside Rollbar's systems, the threat actors searched the company's data for cloud credentials and Bitcoin wallets. The party first tried to launch compute resources, and after that failed for lack of permission, they accessed the data warehouse and ran searches that suggested they were interested in Bitcoin wallets or other cloud credentials.

Rollbar's follow-up investigation found that the attackers had access to its systems for three days between August 9 and August 11, 2023.

While inside Rollbar's servers, they accessed sensitive customer information, including usernames and email addresses, account names, and project information, such as environment names and service link configuration. More importantly, customers' project access tokens that enable them to interact with Rollbar projects were also retrieved during the incident.

Made with 💙 by Wiz

Last Updated: April 3, 2025