← Sumo Logic

2023 Sumo Logic — compromised credential; AWS account intrusion (Nov)

2023 Unknown records affected Share on X

Data compromised

Vendor-stated: no customer dataset theft confirmed; precautionary credential rotation for customers

Technical writeup

Sumo Logic detected suspicious AWS activity on November 3, 2023, tied to stolen credentials (press narratives referenced developer secrets exposed via GitHub-style leakage paths). The company locked down infrastructure, rotated keys, and advised customers as a precaution to rotate their Sumo API tokens and stored integration secrets. Forensics concluded no customer data exfiltration from production datasets, though the event is widely cited as a cloud-credential breach of the vendor’s own environment.

Root cause

Stolen cloud credentials enabling unauthorized AWS account access

References