A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.
Everyone scans repositories for committed secrets. Almost nobody scans the ticket system, which accumulates the same material indefinitely.
700+ organisations queried through one integration’s stolen tokens. Nothing was exploited; the tokens worked exactly as designed.