About 75% of insider incidents involve nobody acting maliciously. Programmes built to detect grievance address a quarter of the problem.
Authentication, authorisation and monitoring all worked. The difference between a legitimate lookup and this one is intent, and intent is not a field.
Recruiting an insider costs money, time and exposure to prosecution. Persuading an agent costs a paragraph and works every time.
Between $2,600 and $5,700 per person, against a sector norm of twenty dollars of credit monitoring. The difference is not generosity.
No vulnerability. Authorised employees performing lookups they were entitled to perform. The security model was not defeated — it was rented.
The operation describing itself, to itself, with no expectation of being read. Nearly everything else in this corpus is an attacker described from outside.
Nobody designs a chat workspace as a data store, and every organisation ends up with one.
Every control answers "should this account reach this data". Here the answer was yes.
No exploit, no malware. Someone kept reading what they had been allowed to read.