Sumo Logic confirms data breach after AWS systems hit

representational image of a cloud firewall
Image Credit: Pixabay (Image credit: Pixabay)

Data analytics and security firm Sumo Logic has suffered a security breach, forcing it to lock down some parts of its system and urge users to rotate their API keys.

According to a BleepingComputer report, the company confirmed the breach, saying it discovered evidence of unauthorized access on Friday, November 3. 

Apparently, a threat actor used stolen credentials to access the company’s Amazon Web Services (AWS) account. “Customer data has been and remains encrypted,” the company added, saying its systems and networks were unaffected by the incident.

Ongoing investigation

"Immediately upon detection we locked down the exposed infrastructure and rotated every potentially exposed credential for our infrastructure out of an abundance of caution," Sumo Logic said. "We are continuing to thoroughly investigate the origin and extent of this incident. We have identified the potentially exposed credentials and have added extra security measures to further protect our systems."

These extra security measures include enhanced monitoring and addressing potential vulnerabilities. Sumo Logic will also continue monitoring network and system logs for further indicators of compromise.

The company also told its customers to update the credentials they use to access its services, as well as any other login information they shared with Sumo Logic.

Besides rotating their API access keys, users should reset Sumo Logic installed collector credentials, third-party credentials stored with Sumo, and user passwords to Sumo Logic accounts.

"While the investigation into this incident is ongoing, we remain committed to doing everything we can to promote a safe and secure digital experience," the company said. "We will directly notify customers if evidence of malicious access to their Sumo Logic accounts is found. Customers may find updates at our Security Response Center."

Sumo Logic is a cloud-based machine data analytics company, with a focus on security, operations, and business intelligence use-cases. It provides log management and analytics services that use machine-generated big data.

The company was founded in early 2010, and is headquartered in Redwood City, California.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
A person holding a virtual cloud in the palm of their hand.
Amazon EC2 instances could be under fire from whoAMI technique giving hackers code execution access
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
AWS S3 feature abused by ransomware hackers to encrypt storage buckets
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
Stress
Time tracker tool spilled details on remote workers - millions of screenshots leaked
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring