Imperva CEO Chris Hylen offers a more detailed post-mortem on what went wrong. The company says it made a critical mistake leaving an internal compute instance containing the AWS API key accessible from the internet. The leaked data included email addresses, salted and hashed passwords, and for some customers, API and TLS keys. Imperva learned of the breach through a third party requesting a bug bounty Its unclear if the security company paid a bounty; Imperva is listed on bug bounty management company HackerOne’s directory.”]
Source: https://www.govinfosecurity.com/impervas-breach-post-mortem-api-key-left-exposed-a-13238