Yes. SendGrid disclosed a security incident on April 27, 2015, after finding that a compromised employee account had accessed internal systems on three dates in February and March. The company said those systems contained usernames, email addresses and salted, iteratively hashed passwords; it also said an attacker accessed servers holding some customer recipient lists and contact information. SendGrid reported no forensic evidence that those lists or contact details had been stolen, but that was the company’s finding at the time—not independent confirmation that access or theft was impossible.
What happened in the 2015 SendGrid incident?
SendGrid’s April 27, 2015 notice described a broader intrusion than the company first suspected. On April 8, a Bitcoin-related customer’s SendGrid account was compromised and used to send phishing emails. SendGrid initially believed the account takeover was isolated. Its subsequent investigation found that a compromised employee account had accessed internal systems on three separate dates in February and March 2015. SendGrid’s incident notice is the company’s account of the event.
SendGrid said affected systems held customer and employee usernames, email addresses, and passwords stored using salted, iterative hashing. It also reported that the attacker accessed servers containing some customer recipient lists or addresses and contact information.
What information did SendGrid say was stolen?
SendGrid stated: “We have not found any forensic evidence that customer lists or customer contact information was stolen.” That describes what the company’s investigation had found when it issued the notice; it does not prove that access to the information was impossible. The notice did not establish a total number of affected customers or a count of stolen lists.
#1 Best Overall
SendGrid said payment card information was not involved because it did not store customers’ payment cards. The company’s account of the incident and its forensic findings were not independently confirmed in the available reporting.
What did SendGrid ask customers to do in 2015?
As part of its response, SendGrid asked customers to reset passwords across SendGrid access points. It recommended enabling two-factor authentication and using unique, randomly generated passwords stored in a password manager.
The company also asked about 600 customers who used custom DKIM keys to generate replacement keys and update their DNS records. This was the number of custom-key customers it asked to take that action—not a count of all customers affected by the incident.
Was the 2021 DKIM key exposure the same breach?
No. The 2021 event was separate from the 2015 intrusion: it involved a publicly accessible Redis cache containing some customers’ private DKIM keys, rather than the employee-account access described in SendGrid’s 2015 notice.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Twilio said a misconfigured Kubernetes network policy exposed the cache for four days, beginning June 14, 2021. A researcher disclosed the issue on June 18. In its account, Twilio said it found no indication that unauthorized actors had accessed the exposed data. See Twilio’s account of the Kubernetes configuration issue. These are Twilio’s reported findings, not independent confirmation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should a SendGrid user do now?
The 2015 password-reset and DKIM-key instructions were incident-era measures. If you currently suspect someone has taken over your account, SendGrid’s support guidance recommends that an administrator review account access, remove unrecognized teammates, use an available two-factor authentication method, and make sure applications and integrations are secure and up to date. These steps are general guidance; they do not show that a particular account was involved in either historical incident. See SendGrid’s account-takeover guidance.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

