Hacker News new | ask | show | jobs
by gmansoor 4461 days ago
BCC every message is evil, as it can be misused as in this case. SendGrid should never allow that, or at least should flag such behavior. At the minimum, they should notified account owners of this change.
1 comments

The attacker got SG to change the email on file, so the notification would just be sent to him.