2017 OneLogin — attacker accessed US database shard with ability to decrypt sensitive fields
Data compromised
Potentially wide credential/secret material depending on encrypted field classes described by vendor
Technical writeup
OneLogin CSO described a threat actor compromising a US-region database shard and obtaining the means to decrypt certain encrypted values after another Amazon credential was used from a US intermediary; Krebs and BBC summarized customer resets and scope.
Root cause
Credential compromise enabling access to encryption-capable infrastructure (per vendor timeline)