CSIDB logo
Incident

Atlassian

Incident posture

Attack window
Feb 2015
Location
Australia
Status
Historical
CIA posture
Available to members
Updated
2026-01-16 13:11

Linked entities

Victim
Atlassian
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity breach at Atlassian compromised names, usernames, email addresses, and encrypted passwords for a small subset (under 2%) of HipChat users, though payment information remained unaffected. The company enforced password resets for impacted accounts and linked services, noting that stolen credentials were protected by salted hashing—a one-way encryption method resistant to straightforward decryption. While this cryptographic measure hindered immediate password exploitation, the exposed personal data created secondary risks, including potential phishing campaigns leveraging the harvested information.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In February 2015, Atlassian disclosed a security breach affecting its HipChat group messaging service. Attackers accessed names, usernames, email addresses, and encrypted passwords for a subset of users, with the company estimating less than 2% of its customer base was impacted. The intrusion did not compromise payment information according to Atlassian's investigation. Craig Davies, Atlassian's security lead, confirmed the stolen passwords underwent one-way encryption using hashing and salting techniques, making them computationally difficult to reverse-engineer. While the exact intrusion method wasn't detailed, the breach necessitated immediate containment measures. Atlassian emphasized the relatively limited scope of affected accounts while acknowledging the seriousness of the credential exposure.

The company initiated a precautionary password reset for all compromised HipChat accounts and any linked Atlassian services sharing the same email addresses. This action aimed to mitigate potential misuse of the stolen password hashes, even though their encrypted state provided substantial protection against straightforward decryption. Atlassian noted that cracking such passwords would require significant computational resources, particularly for complex credentials. However, the breach exposed users to secondary risks, as attackers possessed sufficient personal data to launch targeted phishing campaigns against affected individuals. The incident underscored the importance of password strength, though Atlassian refrained from speculating about potential future attacker actions beyond confirming the immediate containment steps taken. No evidence emerged suggesting further unauthorized access to systems beyond the initially reported data categories.

Sources

Sources available to members: 1 source.

CSIDB