Resend
bd_9cdb48493d2ce692 · schema v1 · pii pii-v1
Resend disclosed that attackers accessed customer data including emails sent, domains, API keys (encrypted), logs, and contacts after discovering an exposed database API key as an environment variable on the client-side of the Resend Dashboard. The actual content of emails was not accessed. The incident occurred between December 30, 2023, and January 9, 2024. Resend rotated keys, enforced MFA, and engaged Oneleet for investigation.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 30, 2023
Begins
Jan 9, 2024
Discovered
Jan 11, 2024
Filed
vs. sector median
18 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.