None
EN
Security ends where the credential does not expire
["Conor O'Sullivan"]
IrishDentist.ie
Years pass but the things that happen are always the same: a 2022 credential, created for a limited pilot project, still valid four years later.
The sequence is simple and disturbing: an old credential opens Klue’s infrastructure; the infrastructure holds customer tokens; tokens open Salesforce environments; data comes out of those environments.
To build a good phishing message you don’t need to know who knows what secrets: all you need is the right name, the right role, the right customer and a real problem already reported to support.
It also notified law enforcement, contacted affected customers and announced a review of credential management, vendor access and monitoring.
Let’s say that a four-year-old credential does not belong to any of these best practices.