Cloudflare blocked phishing campaign

Same 0ktapus campaign. Attack failed due to hardware FIDO2 security keys.

Last modified

Summary

  • Environment: Cybersecurity/CDN
  • Operational impact: Attack failed due to hardware FIDO2 security keys
  • Financial impact: $0 (attack blocked)
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In 2022, Cloudflare experienced an incident in its cybersecurity/cdn environment. The retained source describes the attack path as follows: Same 0ktapus campaign. [1]

The documented consequence was: Attack failed due to hardware FIDO2 security keys. [1]

Impact

  • Documented impact: Attack failed due to hardware FIDO2 security keys. [1]
  • Documented financial consequence: $0 (attack blocked). [1]

Timeline

  1. Documented public update

    The The mechanics of a sophisticated phishing scam and how we stopped it records the incident facts used in this briefing.

    [1]
  2. Briefing updated

    This briefing was last reviewed and updated on September 19, 2026.

Threat Group & Attack Vector

The retained source describes the attack path as follows: Same 0ktapus campaign. The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • 0ktapus — identified in the supported attack description. [1]

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The retained source describes containment action intended to limit further access or disruption. [1]

This account is bounded to The mechanics of a sophisticated phishing scam and how we stopped it. Details absent from that evidence are left unresolved rather than inferred. [1]