Extortion refused, 234 GB published, 2.6 million addresses verified. The refusal produced a record that payment never does.
A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.
A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.
Mass credential compromise across tens of thousands of firewalls. Patching fixes the device; it does not un-disclose the credentials.
Holiday timing is not a coincidence. And a resident who needs a permit has exactly one place to get it.
Half the compromised accounts in Asia belong to people about whom this corpus can say nothing further.
A crash report exists because someone was in a collision. No vulnerability was exploited — a valid account did a permitted thing 300,000 times.
No credential stolen, no server compromised, no employee deceived. The contract executed exactly as published — the specification and the intent diverged.
No zero-day, no custom tooling, no organisation. One person in their late teens and a credential without MFA.
The corpus has been over-weighting the minority route, because a named CVE generates documentation and a stolen password does not.
A support portal is a production system. 18,000 schools did not make 18,000 bad decisions — but the security did not scale with the concentration.
Containment converts an unbounded loss into a bounded one, and moves it onto whoever needed the service that week.