← JumpCloud

2023 JumpCloud — nation-state spear-phish; commands-framework abuse (subset of customers)

2023 Unknown records affected Share on X

Data compromised

Tenant-dependent; incident framed around device execution and session material for impacted orgs rather than wholesale directory exfiltration

Technical writeup

JumpCloud disclosed a June–July 2023 intrusion in which a spear-phished employee device gave a North Korea–attributed actor developer-tier access, lateral movement into container orchestration, and injection into the customer “commands” path to steer a small set of tenant devices toward follow-on malware. Public remediation included forced administrator API key rotation and infrastructure rebuild narratives; press and IR partners cited single-digit customer and device counts rather than mass tenant data loss.

Root cause

Targeted spear-phishing leading to insider-tier access and abuse of JumpCloud command-delivery mechanisms (DPRK-nexus attribution in vendor and partner reporting)

References