Incidents

Active investigations · demo data

Demo environment · simulated telemetry. Predictions and simulations are estimates with stated confidence, never guarantees.

INC-2471

Stale OAuth grant to ledger signing key

Open attack path ↗

Observed situation

A 214-day-old OAuth grant belonging to Mira Chen was refreshed from an unfamiliar network and used to assume svc-ledger-prod, which then read the payments signing key. Three hops are confirmed by telemetry; everything past the key is modelled, not observed.

Predicted next step

Forge a signed request to the payments API to confirm the key is still accepted (72% · next 3–6 minutes)

Business impact

Unauthorised transaction signing at production scale, with settlement reversal costs and a likely payment-scheme notification if forged signatures reach the ledger.

Data exposure

Up to 2.4M customer records and the identity documents held in customer-vault, triggering regulated breach reporting.

Blast radius · 76

ElevatedInitial asset: mira

Confidence · 87%

Prioritised on risk 94, business impact 91, exploitability 88 and privilege escalation 93.

Evidence

  • ·08:57 · Grant refresh from ASN not seen in 90 days of history
  • ·08:58 · First AssumeRole by oauth-grant-7f2c in 214 days
  • ·08:59 · prod-secret-42 read; prior read 41 days earlier
  • ·09:00 · 1.4k control-plane events under the assumed role
  • ·Behavioural divergence 4.8σ from the identity's 30-day baseline

Security time machine

Reconstruction

Open timeline ↗

Initial event

Credential phishing landing page visited

Identity change

Dormant OAuth grant reactivated

Permission change

Service-account assumption via delegated grant

Access

Secrets read from production scope

Lateral movement

Signed request accepted by payments service

Attempted data access

Enumeration query against customer vault

Defensive intervention

OAuth grant revocation authorised