2023 New Relic — staging environment access; credential theft & social engineering (NR23-01)
Data compromised
Staging observability query results for internal datasets; separate customer ATOs attributed to unrelated campaigns
Technical writeup
New Relic’s NR23-01 advisory described unauthorized access beginning in late October 2023 to a staging environment containing internal observability data (not production customer-applied telemetry). An actor used stolen credentials and social engineering against an employee account, ran searches, and exfiltrated a subset of query results. The firm also observed takeovers of a small number of customer accounts but attributed those to broader credential-stuffing rather than the staging path. New Relic rotated secrets, revoked access, and later accelerated API-key architecture changes.
Root cause
Credential theft plus social engineering against internal staging access