based on auth logs, api and lack of traffic anomalies in the last 14 days, no database information was exfiltrated. looks like just a public defacement specifically targetting me
Timeline
Post
Remote status