The digital security firm suffered a widespread credential stuffing campaign targeting its customer base. Automated botnets successfully crossed reference historical third-party data dumps to breach thousands of individual customer accounts, exposing stored password vault metadata.