If a transgression by a single employee breaches your network, you're doing it wrong.
@dangoodin To my (largely untrained) eyes, some big red flags seem to be
1. They didn't have an intrusion detection system that flagged this (it seems like a new IP/host accessing a service account from likely a new subnet would be notable) and it sounds like they only found out once their customers notified them.
2. Relying on password-based authentication rather than key/certificate-based authentication for remote access to a service account without strong compensating controls (like limiting it to specific hosts)
3. Once they knew their customer had been breached they couldn't just look at the access logs for the affected account and verify in short order that there were hosts for which they couldn't account.
But I'm curious what those with more knowledge think on those points.