Forum Moderators: open
"OneLogin believes that all customers served by our US data center are affected and customer data was potentially compromised,"
Later in the day, the company said in an update: "Our review has shown that a threat actor obtained access to a set of [Amazon Web Services, or AWS] keys and used them to access the AWS API from an intermediate host with another, smaller service provider in the US." OneLogin Password Manager Hacked [zdnet.com]
"Our review has shown that a threat actor obtained access to a set of [Amazon Web Services, or AWS] keys and used them to access the AWS API from an intermediate host with another, smaller service provider in the US."So they're *not* saying TLS v1.2 is hackable or that data security hashing is unsecure, only that their data was hackable. So it's their failure... that's what's important IMO.