WHY IT MATTERSWhy this changes the risk
This matters because credential-based access can expose information that customers expect their service provider to protect, even when the report does not establish the campaign’s origin or full scope.
Personal data and billing records may be sensitive, so affected subscribers may need to distinguish legitimate provider communications from phishing attempts that exploit the warning. The absence of reported account totals, credential source, or misuse findings limits conclusions about severity.
Still, the multi-month duration makes prompt account review and careful verification of follow-up messages reasonable, without implying that every customer was affected or that further harm occurred.