wlanboy
Content Contributer
See: https://sendgrid.com/blog/update-on-security-incident-and-additional-security-measures/
FUBAR.On April 8, the SendGrid account of a Bitcoin-related customer was compromised
and used to send phishing emails.
We initially believed that this account takeover was an isolated incident and worked
with our customer to help them recover control of their account and minimize the damage of the attack.
After further investigation in collaboration with law enforcement and FireEye’s (Mandiant) Incident Response Team,
we became aware that a SendGrid employee’s account had been compromised by a cyber criminal and
used to access several of our internal systems on three separate dates in February and March 2015.
These systems contained usernames, email addresses, and (salted and iteratively hashed) passwords for
SendGrid customer and employee accounts. In addition, evidence suggests that the cyber criminal accessed
servers that contained some of our customers’ recipient email lists/addresses and customer contact information.
Last edited by a moderator: