A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.
More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.
Everyone scans repositories for committed secrets. Almost nobody scans the ticket system, which accumulates the same material indefinitely.
700+ organisations queried through one integration’s stolen tokens. Nothing was exploited; the tokens worked exactly as designed.
A sequel name is a judgement that this is the same mistake in the same place. Session tokens leak past authentication entirely.
No credential stolen, no server compromised, no employee deceived. The contract executed exactly as published — the specification and the intent diverged.
A token signed with a trusted key is not a forgery the platform can detect. It is a valid token.
The credential that mattered was not the password. It was the thing issued after the password.
The security of a system is the security of everyone it has delegated to — a set nobody enumerates.