Dropbox Sign (formerly HelloSign) data breach
sign.dropbox.com
sign.dropbox.com
API keys were leaked as part of this hack. It's unclear from press release if hackers used the API keys to access data/documents of customers.
April 24th they became aware of issue, reporting it over a week later. I'd also be curious on how long this problem went on before being detected on April 24?
I suppose more will come out in the coming days...
(this item was first, but the other has more traction)