A Password Nobody Remembered Just Took Down 200 Companies — Including the Ones That Sell Security.
In 2022, a software company issued a single credential for a small pilot project. The pilot ended. The credential was never turned off. Four years later, attackers found it, walked in, and used it to steal data from roughly 200 of the company's customers — including several of the most respected cybersecurity firms in the world. No malware. No exploit. Just a login that everyone forgot existed.
Somewhere in a company's systems in 2022, someone created a credential. It was for a limited pilot — a trial integration, a proof of concept, the kind of small project that happens constantly at software companies. The pilot did what pilots do: it ran for a while, produced its result, and ended. The integration was abandoned. Everyone moved on.
The credential was never revoked.
For four years it sat there — valid, active, forgotten. Not monitored, because nobody remembered it existed. Not rotated, because it wasn't on anyone's list. Not disabled, because the project it belonged to was over and out of mind. It was a working key to the building, left under a doormat that everyone had stopped looking at.
In June 2026, attackers found it. And what happened next is one of the most instructive breaches of the year for any business that relies on outside vendors, cloud tools, or third-party integrations — which is to say, every business.
companies had data stolen because of one forgotten credential — including several major cybersecurity firms
The company that owned the credential was a market intelligence platform used by hundreds of businesses. Attackers used the dead credential to get in, then harvested the digital keys that connected the platform to its customers' systems — and used those keys to reach into roughly 200 customer environments and steal their data. The victims included some of the best-known names in cybersecurity. The irony was not lost on anyone.
Here's the part that matters for your business: the initial breach didn't require any sophistication at all. No zero-day exploit. No advanced malware. No nation-state tooling. The attackers logged in with a credential that should have been switched off years earlier. The sophistication came afterward — but the front door was opened with a key that was left lying around.
How one dead credential became 200 breaches
The mechanics of this attack are worth understanding because they illustrate exactly how modern supply-chain breaches cascade. Here's the sequence:
The pivot point — the thing that turned one compromised vendor into 200 breached companies — was the OAuth token. An OAuth token is a digital key that lets one app access your data on another service without needing your password. When you click "Connect to Google" or "Sign in with Microsoft" to link a tool to your systems, you're issuing an OAuth token. It stays valid until someone revokes it. Most businesses have dozens of these connections and have never audited a single one.
Why this is a small business story, not a big company story
It's tempting to read this as a story about big software companies and their big customers. It isn't. It's the most universal breach in this entire series, because the root cause — a forgotten credential and unaudited third-party access — exists in essentially every small business, usually in greater quantities than in large ones.
Think about your own systems. The contractor you gave access to for a project in 2023 — is their login still active? The accounting tool you trialed and abandoned — did you revoke its connection to your bank feed? The former employee's account — fully deactivated, or just "we changed the password"? The marketing app someone connected to your Google Workspace two years ago and stopped using — is that OAuth token still live? The vendor who needed temporary access to your systems and never got switched off?
The four things to do this week
Audit your OAuth connections — the keys you forgot you handed out
30 minutes · FreeEvery "Sign in with Google/Microsoft" connection and every app you linked to your email, storage, or CRM is an OAuth token that stays live until revoked. Most businesses have dozens. The abandoned ones are pure risk with zero benefit.
Build a credential offboarding habit — for tools and contractors, not just employees
Policy · FreeMost businesses have an offboarding process for departing employees. Almost none have one for abandoned tools, ended contracts, or completed projects. The dead credential in this breach existed because a pilot ended and nobody had a step that said "revoke the access we created for it."
Ask your critical vendors one question
Vendor risk · Free48% of breaches now come through a third party. The vendors holding your data are part of your attack surface, and you're allowed to ask them about it. The businesses breached here were victims of their vendor's forgotten credential — a risk they could have asked about.
Remember that MFA doesn't cover authorized connections
Awareness · CriticalThe uncomfortable lesson of this breach: MFA protects your login, but it doesn't protect the connections you've already authorized. An OAuth token is a standing permission. Once granted, it doesn't get re-challenged by MFA. That's why token audits matter as much as strong authentication.
The one sentence that summarizes the whole breach
Roughly 200 companies — including firms whose entire business is protecting other companies from exactly this — had their data stolen because a login created for a small project in 2022 was never switched off. Not a sophisticated attack. Not an unstoppable adversary. A forgotten key.
The attackers in this story didn't do anything most SMBs would consider advanced to get in. They found something that was left on. The lesson isn't that you need better technology. It's that the access you've already granted — and forgotten — is very likely your largest unguarded risk. It costs nothing to go turn off the keys you're no longer using. It costs a great deal to explain to your customers why you didn't.
📚 Credential Security Series — Read the full series
Find the forgotten keys before someone else does. Veriti Spottr's beta is free.
Get your CyberScore →
Comments
Post a Comment