In the Salesloft incident filed at 25-0818, attackers exported contact data, case records and — critically — API keys embedded in tickets and attachments. Cloudflare disclosed that 104 API tokens and sensitive case data were compromised, and rotated them.
This Is The Third Time This Database Has Filed The Same Thing
The EY compromise at 26-0713 turned on documents attached to IT support tickets. The Adobe claim at 26-0322 concerned 13 million support tickets. Here the tickets contained live credentials.
A support ticket exists to reproduce a problem, and reproducing an API problem means pasting the API call — with the token in it. Nobody decides to store secrets in a CRM; it happens one troubleshooting session at a time.
Why The Secret Scanning Everyone Deployed Does Not Catch This
Organisations have invested substantially in scanning source repositories for committed credentials, and that investment works. Almost nobody scans their support ticket system.
It is not classified as a place where code lives, so it falls outside the tooling’s scope — while accumulating exactly the same material, with a far broader internal readership and typically indefinite retention.
Disclosing The Number Is The Notable Behaviour
Publishing a specific count of exposed tokens is unusual. It invites the question of why they were there, which is not a flattering conversation.
It is also the thing that makes the incident useful to everyone else. A precise figure from a capable organisation is what turns "check your ticket system" from generic advice into a plausible estimate of what any peer would find.
Compiled from company disclosure and published research, listed below. The token count is the company’s own figure. See 25-0818 for the incident. Corrections: corrections@forensicpost.com.