Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Managing Risk When a Core Internet Provider Has a Bug

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2017, written in 2026 with the benefit of hindsight.

The short version: In 2017, a bug at Cloudflare, a major internet provider, leaked private data from customer websites, including login sessions. The websites did nothing wrong. A supplier's bug exposed them.

Why this matters to you

Your company relies on providers that sit between your customers and your systems: content delivery networks, firewalls in the cloud, identity providers, email filters. They see your traffic and often your customers' login sessions. When they have a problem, you inherit it.

The business impact

  • Account takeover risk for your customers and employees if session tokens leak.
  • Response cost: forcing everyone to sign in again and rotating keys takes time and causes friction.
  • Disclosure questions: you may need to tell customers about an incident you did not cause.

Questions to ask your team

  • Which providers can see our customers' or employees' login sessions or passwords?
  • If one of them announced a leak today, how quickly could we reset everything exposed?
  • Do we know where all our keys and passwords for other systems are stored?
  • Who reads our providers' security notices?

What good looks like

A short list of critical providers, a documented rotation plan, secrets kept in a managed vault, and a team that has practiced resetting them.

The decision

You cannot stop a supplier's bug. You can control how fast you recover. Ask for a provider-incident runbook and a test of it this year — it is one of the cheapest forms of resilience you can buy.

cloudbleed impactCloudbleed2017

More on this story