* They stress that the compromised account wasn't able to "create/delete users or download customer databases", but not what it could do. Could it change passwords of accounts and add 2fa methods, allowing them to take over rarely/never accessed users? Disable 2fa? Change account permissions? List user accounts and metadata to build a user account DB for further attacks? The application is named "SuperUser" ...
* It took public posting of a screenshot to trigger an audit of access logs, two months after the compromise was detected!
* "Only" 2.5% of customers were accessed. That's supposed to be a good thing? Those were certainly the most valuable targets.
* Concludes everything is just fine and no corrective actions need to be taken, but affected customers might want to do their own analysis... Huh?
Sounds a lot like damage control.