2019 Segment — attacker used compromised employee credentials to access a limited set of customer workspaces and API write keys
Data compromised
Names, emails, IPs, and Segment write keys for the impacted workspaces—categories differ by customer relationship per notice-era summaries.
Technical writeup
Segment emailed customers describing unauthorized access via a compromised internal account that enabled read-oriented access to a small number of workspaces and associated write keys; outlets and community threads summarized rotations, law-enforcement coordination, and scope as confined to thirteen workspaces in early reporting.
Root cause
Account takeover of an internal Segment employee login enabling misuse of admin/support-style access paths (per customer notice summaries).