# April 2022 Incident Review

DevFeed: [April 2022 Incident Review](<https://devfeed.tech/articles/april-2022-incident-review-26374.md>)

Original publisher: [Read original article](<https://www.heroku.com/blog/april-2022-incident-review/>)

Author: Bob Wise

Published: 2022-06-14T22:37:31Z

Content type: article

Language: en

Sources: [Heroku](<https://devfeed.tech/sources/heroku.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Heroku](<https://devfeed.tech/topics/heroku.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [github](<https://devfeed.tech/tags/github.md>), [incident](<https://devfeed.tech/tags/incident.md>), [news](<https://devfeed.tech/tags/news.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

## AI overview

Heroku's April 2022 incident review describes an investigation into unauthorized access that Salesforce concluded was part of a supply-chain attack. It outlines the threat actor's actions, containment measures, credential rotation, integration changes, and planned security improvements involving GitHub and OAuth.

## Source excerpt

We have concluded our investigation and want to provide our customers with an overview of the threat actor's actions, direct mitigations we have taken because of this incident, and additional changes we will make in the face of a continually evolving threat landscape. Our incident summary outlines what we have learned during the course of [...] The post April 2022 Incident Review appeared first on Heroku.