There were a lot of doomsday predictions in yesterday's thread before any real info had been shared, but it was always the more likely scenario that a support agent contracted through a vendor would have limited read access to their internal systems and wouldn't be able to cause any real damage.
you can do a lot of damage with read access depending on what you're able to read
Everyone's terrible with secops, but Okta employees were apparently dumping AWS keys into public channels.