Demo environment · simulated telemetry. Predictions and simulations are estimates with stated confidence, never guarantees.
INC-2471
Stale OAuth grant to ledger signing key
Observed situation
A 214-day-old OAuth grant belonging to Mira Chen was refreshed from an unfamiliar network and used to assume svc-ledger-prod, which then read the payments signing key. Three hops are confirmed by telemetry; everything past the key is modelled, not observed.
Predicted next step
Forge a signed request to the payments API to confirm the key is still accepted (72% · next 3–6 minutes)
Business impact
Unauthorised transaction signing at production scale, with settlement reversal costs and a likely payment-scheme notification if forged signatures reach the ledger.
Data exposure
Up to 2.4M customer records and the identity documents held in customer-vault, triggering regulated breach reporting.
Blast radius · 76
ElevatedInitial asset: mira
Confidence · 87%
Prioritised on risk 94, business impact 91, exploitability 88 and privilege escalation 93.
Evidence
- ·08:57 · Grant refresh from ASN not seen in 90 days of history
- ·08:58 · First AssumeRole by oauth-grant-7f2c in 214 days
- ·08:59 · prod-secret-42 read; prior read 41 days earlier
- ·09:00 · 1.4k control-plane events under the assumed role
- ·Behavioural divergence 4.8σ from the identity's 30-day baseline
Security time machine
Reconstruction
Initial event
Credential phishing landing page visited
Identity change
Dormant OAuth grant reactivated
Permission change
Service-account assumption via delegated grant
Access
Secrets read from production scope
Lateral movement
Signed request accepted by payments service
Attempted data access
Enumeration query against customer vault
Defensive intervention
OAuth grant revocation authorised