On 3 November 2023, Sumo Logic, a cloud log management and security analytics company, discovered that someone had used a compromised credential to access one of its AWS accounts. It disclosed the incident on 7 November, said it had locked down the exposed infrastructure and rotated every potentially exposed credential, and asked customers to rotate the credentials they used with Sumo Logic, starting with API access keys. Because a log analytics platform holds its customers' keys to other systems, the advice also covered installed collector credentials, third-party credentials stored for data collection and webhook configurations, and user passwords, although Sumo Logic narrowed the precautionary list a day later. On 21 November it closed the investigation, saying it had found no proof of customer data impact, a finding verified by third-party forensic experts. Sumo Logic did not say how the AWS credential was compromised.
Key takeaways
- A compromised credential was used to access a Sumo Logic AWS account; the company found evidence on 3 November 2023.
- Sumo Logic rotated every potentially exposed credential in its own infrastructure.
- It asked customers to rotate API access keys and, as a precaution, credentials they had stored with Sumo Logic for other systems.
- Its investigation, verified by third-party forensic experts, found no proof of customer data impact.
- The identity lesson: a SaaS provider that stores customers' credentials is part of their attack surface, and fast key rotation depends on knowing where every key lives.
At a glance
| Organisation | Sumo Logic (cloud log management and security analytics) |
|---|---|
| When | Discovered 3 November 2023; disclosed 7 November 2023; closed 21 November 2023 |
| Attacker | Unattributed |
| Entry point | A compromised credential for a Sumo Logic AWS account; how it was compromised was not disclosed |
| Identities abused | An AWS account credential |
| Impact | Unauthorised access to an AWS account; credential rotation for Sumo Logic and its customers; no customer data impact found |
| Category | NHI. Incident class: confirmed NHI breach (compromised cloud credential) |
What happened
Sumo Logic's security notice said: "On Friday, November 3rd, 2023, Sumo Logic discovered evidence of a potential security incident. The activity identified used a compromised credential to access a Sumo Logic AWS account." It added: "We have not at this time discovered any impacts to our networks or systems, and customer data has been and remains encrypted." The company said: "Immediately upon detection we locked down the exposed infrastructure and rotated every potentially exposed credential for our infrastructure out of an abundance of caution."
It then turned to customers. SecurityWeek reported that users were advised to "rotate credentials that are either used to access Sumo Logic or that you have provided to Sumo Logic to access other systems," with API access keys the most urgent. Help Net Security listed the other precautionary items: installed collector credentials, third-party credentials stored for data collection, such as S3 access, or in webhook configurations, and user passwords. On 8 November, Help Net Security reported that Sumo Logic had narrowed the extra precaution to third-party credentials stored as part of webhook connection configuration.
On 21 November, Sumo Logic said it "uncovered no proof of customer data impact and no threat of customer data impact present. These findings were verified by third-party forensic experts and the investigation of this incident is now complete and closed." The Register quoted Jason Kent of Cequence Security: "If it is painful to rotate the keys when there is no urgency, imagine how much harder it will be if you really need to get it done quickly."
Timeline
| Date | Event |
|---|---|
| 3 November 2023 | Sumo Logic finds evidence of a compromised credential used to access an AWS account. |
| 7 November 2023 | Sumo Logic discloses the incident and asks customers to rotate credentials. |
| 8 November 2023 | Sumo Logic narrows its additional precautionary advice to webhook credentials. |
| 21 November 2023 | Sumo Logic closes the investigation, finding no proof of customer data impact. |
How it happened: the identity attack path
- Credential compromised. A credential for a Sumo Logic AWS account was compromised; how is not public.
- Cloud account accessed. The credential was used to access the AWS account.
- Detection. Sumo Logic found evidence of the activity on 3 November.
- Containment. It locked down infrastructure and rotated every potentially exposed credential.
- Customer rotation. Customers were asked to rotate API keys and stored third-party credentials.
Impact
- Accessed: a Sumo Logic AWS account.
- Customer data: no proof of impact, according to Sumo Logic's investigation.
- Operational cost: credential rotation across Sumo Logic and its customer base.
What this means for NHI governance
Observability and security analytics platforms sit in an unusual position: to collect data they hold their customers' cloud keys, webhook secrets and collector credentials. A compromise of the provider's own cloud credentials therefore puts customers' non-human identities in question too, even when no data is taken. That is why Sumo Logic's first request was for customers to rotate.
The incident is also a test of rotation readiness. Organisations that knew which Sumo Logic keys they used, and where third-party credentials were stored, could respond in hours. See our API Key Management Guide and Third-Party Access Guide.
Recommendations
- Keep an inventory of keys shared with vendors. Know which credentials each SaaS provider holds. See our Third-Party Access Guide.
- Practise rotation. Rotate API keys on a schedule so an emergency rotation is routine. See the API Key Management Guide.
- Prefer short-lived cloud credentials. Use role assumption instead of long-lived AWS keys. See the Cloud Workload Identity Guide.
- Scope what vendors can reach. Give collectors read-only access to only the data they need. See the Secrets Management Guide.
- Follow vendor advisories quickly. Treat a vendor's rotation request as an incident. See the Leaked Credential Response Playbook.
Frequently asked questions
What happened in the Sumo Logic breach?
A compromised credential was used to access a Sumo Logic AWS account. Sumo Logic discovered it on 3 November 2023 and disclosed it on 7 November.
Was Sumo Logic customer data stolen?
Sumo Logic said its investigation, verified by third-party forensic experts, found no proof of customer data impact.
Why did customers need to rotate credentials?
Customers use API keys to access Sumo Logic and store credentials with it to collect data from other systems, so a provider compromise put those keys in question.
Related NHI Mgmt Group resources
Okta Support System Breach 2023 · Codecov Breach 2021 · API Key Management Guide · Third-Party Access Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
When a vendor is breached, your keys are in question too. We help teams map the credentials held by providers and rotate them quickly. See our NHI and AI agent security training.
References
- Help Net Security: Sumo Logic discloses potential breach via compromised AWS credential (8 November 2023)
- SecurityWeek: Sumo Logic Urges Users to Change Credentials Due to Security Breach (8 November 2023)
- Security Affairs: Sumo Logic discloses security breach (8 November 2023)
- The Register: Sumo Logic says customer data untouched during breach (21 November 2023)