Also, it is a big deal because (as a former support person I know this), users often send in sensitive info with their support requests: SSNs, full credit card info with CVV data, date of birth (yes, sometimes all in the same message).
And two, the body of the emails was not exposed, only the subject line. People typically don't but their SSN in the subject line...
Obviously you can also take the opinion that this should have never happened and question their competence and security. I personally weigh their response and transparency more than the issue itself, but it may seem easier since the impact to overall customers was relatively small.
Their response seems to have been handled well and may even generate some positive PR. That may change if it turns out to have been one of the recent Rails security flaws.
Well done Zendesk.
For the record, when I wrote the above comment, the headline of this thread was "Zendesk was hacked, 3 customers affected". It has been changed since, without due notice of course. I wonder why...
Now, my comment looks like I'm a nutjob and have a personal gripe with Zendesk or something.
That the three customers were Twitter, Pinterest and Tumblr didn't come out until later as well.
Carry on.