Resend disclosed that attackers accessed customer data including emails sent, domains, API keys (encrypted), logs, and contacts after discovering an exposed database API key as an environment variable on the client-side of the Resend Dashboard. The actual content of emails was not accessed. The incident occurred between December 30, 2023, and January 9, 2024. Resend rotated keys, enforced MFA, and engaged Oneleet for investigation.