Valid credentials from somebody else’s breach, accepted. Nothing failed in the conventional sense, and customer data went anyway.
A crash report exists because someone was in a collision. No vulnerability was exploited — a valid account did a permitted thing 300,000 times.
The corpus has been over-weighting the minority route, because a named CVE generates documentation and a stolen password does not.
A number is not a name until somebody looks it up, and looking it up is trivial. What the set contains is a contact graph.
It did not grow because the intrusion grew. It grew because working out whose records sit in four terabytes takes eleven months.
A 560 million claim graded low sits below a 110 million disclosure graded high. That ordering is the point of having grades.
The platform behaved correctly at every step and 165 organisations lost data anyway. There was no CVE to index it under.
Encryption is the moment the attacker chooses to be seen. It happens after the theft, because the theft is the leverage.
A written requirement that MFA be enabled everywhere is not a control. It is intent somebody then has to enforce against an estate nobody has fully inventoried.