> For active customers, sFTP and database usernames and passwords were exposed. We reset both passwords.
> For a subset of active customers, the SSL private key was exposed. We are in the process of issuing and installing new certificates for those customers.
Wow.. That's quite severe.. From September 6th to November 17th.. I wonder will they do a full impact summary after they figure it out internally.