ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Bug tracking firm Rollbar says hackers accessed clients' sensitive data

Rollbar, a US-based software bug-tracking company, suffered a significant cyber attack that compromised the sensitive and confidential information of its clients.The news of the data breach came to light earlier in September when security researcher Troy Hunt shared the company’s data breach notification on X, formerly Twitter.Rollbar said in its notification to affected clients that on September 6, it identified “irregularity in our data warehouse query log” and immediately launched an internal investigation to understand the nature and scope of the cyber security incident.

 

“Our preliminary analysis established that a cloud platform service account which only had access to our data warehouse was used by an unauthorised party,” the company said. “When we became aware of this access we disabled the service account and began analysing what actions had been taken by the unauthorised party.”The investigation further revealed that the threat actors infiltrated Rollbar’s internal systems between August 9, 2023 and August 11, 2023.“The party first tried to launch computer resources, and after that failed for lack of permission, they accessed the data warehouse and ran searches that suggested they were interested in Bitcoin wallets or other cloud credentials,” Rollbar added.Within the three days the threat actors had access to Rollbar’s systems, they accessed confidential data of the company’s clients, including their usernames and user email addresses, account names,  project and environment names, project access tokens, and project service link configuration details.Rollbar said that it will engage third party cyber security experts to verify its findings and work with them to resolve the matter. The company added that access tokens allowing access to Rollbar project data with read and write options have expired and can be refreshed by using the Rollbar UI. API, or Terraform provider.The company added that project tokens allowing access to send data to an active project will expire in 30 days. “Although our investigation is ongoing, we hold the security of our customers’ data paramount and are therefore writing to promptly notify you of the discovery and the steps we have taken,” Rollbar added.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543