The big picture here is that three
customers' data was compromised -- customers in this context means entire platforms using Zendesk for support, not users. If the customers were, say, WePay, Box.net and OpenTable (random companies taken from their portfolio), this is potentially hundreds of thousands of users.
Also, it is a big deal because (as a former support person I know this), users often send in sensitive info with their support requests: SSNs, full credit card info with CVV data, date of birth (yes, sometimes all in the same message).