Sendgrid has become an increasing source of abuse for me over the last year, but I do a lot of contact management (e.g., disposable email addresses), so I'm not at all surprised that other people have had problems with them for many years.
I'm also suspicious about the self-reported "hacked" angle. How many times have we heard that same story when someone does something awful online and tries to shirk responsibility? I find it far more likely that someone inside Sendgrid (or their client companies) is trying to make some extra cash on the side. If it were legitimate cracking going on, I'd expect to hear more about what Sendgrid has actually done to tighten up their security, not this "Oh, maybe we'll get around to requiring 2FA some day" nonsense.
Honestly, at this point, I don't see any mass senders as legitimate unless they are offering a cash bounty for anyone who reports spam coming from their systems. I gave up on reporting abuse to the abusers a long time ago because, at best, all I got back was a "we can't respond to all complaints, but we'll take action that *we* think is appropriate" boilerplate. Decades of anti-spam rhetoric like that hasn't accomplished anything. The day I can collect even $1 in compensation for attacks on my servers is the day I'll finally believe that being abusive isn't part of the business model for these companies.
c51e645d5465ba1674a115823125f264a4b540c68faedd03fdf38fcbc438aee0