> Additionally, we have no evidence that the attacker has accessed any customer accounts or decrypted customers’ environment variables. Now the attackers had access to encrypted environment variables?
> We also wanted to address a question regarding impact to environment variables. While we confirmed that the threat actor had access to encrypted Heroku customer secrets stored in config var, the secrets are encrypted at rest and the threat actor did not access the encryption key necessary to decrypt config var secrets.