* a third party has barely restricted, deep access to all customer data
* the "SuperUser" app can apparently have logged in users idling around in a VM, waiting for someone to come along and use it without any automatic logout and re-authentication
* a single account accessing 300+ customers in a few days doesn't trigger any alerts
* they detect a compromise, and do absolutely nothing about it for months, except letting the third party order a security audit; they patiently wait for a report; they don't even audit the access logs
* only a screenshot posted online triggers an audit of access logs and a public response
* they still try to blame the third party and the security firm for their own (basically outrageous) inactivity
All of this by a company entrusted with the most critical gatekeeping functionality of systems, used by many large enterprises and expected to have top notch security.