Years pass but the things that happen are always the same: a 2022 credential, created for a limited pilot project, still valid four years later. The sequence is simple and disturbing: an old credential opens Klue’s infrastructure; the infrastructure holds customer tokens; tokens open Salesforce environments; data comes out of those environments. To build a good phishing message you don’t need to know who knows what secrets: all you need is the right name, the right role, the right customer and a real problem already reported to support. It also notified law enforcement, contacted affected customers and announced a review of credential management, vendor access and monitoring. Let’s say that a four-year-old credential does not belong to any of these best practices.