2023 Sumo Logic — compromised credential; AWS account intrusion (Nov)
Data compromised
Vendor-stated: no customer dataset theft confirmed; precautionary credential rotation for customers
Technical writeup
Sumo Logic detected suspicious AWS activity on November 3, 2023, tied to stolen credentials (press narratives referenced developer secrets exposed via GitHub-style leakage paths). The company locked down infrastructure, rotated keys, and advised customers as a precaution to rotate their Sumo API tokens and stored integration secrets. Forensics concluded no customer data exfiltration from production datasets, though the event is widely cited as a cloud-credential breach of the vendor’s own environment.
Root cause
Stolen cloud credentials enabling unauthorized AWS account access