SendGrid: Reset all customer passwords after breach
SendGrid is resetting passwords for all its customers after research emerged suggesting that the cyberattack it carried out earlier this month was more extensive than previously thought.

The company, which provides other businesses with a service to send mass emails without being blocked, said earlier this month that a Bitcoin-related customer's account was hacked and used to send the phishing emails.
"Further investigation by FireEye's Mandiant division also revealed that the attackers also compromised a SendGrid employee's account, giving them access to the company's internal systems for over three days in February and March," wrote David Campbell, the company's chief security officer.
The attackers would have had access to the usernames, email addresses, and passwords of SENDGRID customers and its employee accounts, Campbell wrote. The attackers also had access to the central servers that contain customer email lists, as well as information . Payment card information was not compromised, since SENDGRID does not store it.
"We have not found any evidence that customer lists or customer contact information were stolen," Campbell said.
"However, as a precautionary measure, we are implementing a system-wide password reset."
SendGrid sends 14 billion emails per month to 180,000 customers, according to its website.
Compromising a provider like SendGrid is very useful for cyberattackers since it is their specialty to send emails that are not blocked by spam filters.
SENDGRID customers are recommended to install two-factor authentication.
The company is also working on another security measure, API Keys, which will allow administrators to generate authentication certificates that are separate from usernames and passwords. These keys can be generated for different applications and servers, making it easier to revoke one without extensive disruption of services, according to SENDGRID's website.

