A leading cloud services provider disclosed that attackers accessed personal data belonging to 8.4 million customer accounts after exploiting a misconfigured API gateway left exposed during a routine infrastructure migration.
The exposed data included names, email addresses, hashed passwords and, for a subset of business customers, billing contact details. The company said payment card numbers were not affected as they are stored in a separate tokenized vault.
Forensic analysis indicates the attackers ran automated harvesting scripts for roughly three weeks before anomalous traffic patterns triggered an internal alert. The company has forced password resets and notified regulators in multiple jurisdictions.
Security analysts noted that API misconfigurations have become one of the leading causes of large-scale data exposure, urging companies to adopt continuous configuration auditing rather than periodic reviews.
