- What was extracted at the time
- Usernames and passwords. The archive was password-protected and partially malformed, so everything past the credential block was skipped.
- What was actually in it
- Session cookies, an OAuth refresh token, autofill data including a corporate address, and browser history showing which internal tools the machine reached.
- What changed
- Our extraction improved. Because we still held the archive, we re-ran it — and the token was still valid. Nothing new was stolen; we simply became able to read what we already had.