- Live, not inferred
- A single authenticated request returned a real success response rather than a guess from the shape of the key. The storage key was live and unrotated with read, write and delete across every container. Of the two platform keys, one was live and unrestricted; the other had expired, and was reported as expired.
- Quantified, not asserted
- Container and object metadata were enumerated to size the exposure: well over 100 GB of daily conversation logs across several thousand files, spanning roughly eight months and still being written to — live, not historical. A bounded read-only sample, well under a tenth of one percent of the corpus, then characterised what the data was, and every count taken from it was reported as a floor.
- Where it stopped being a hygiene ticket
- The same key held write access to the secret key stores behind the platform's serverless functions. An attacker writing their own key material there is adopted by the runtime — and control of that platform is the ability to message customers from the brand's own verified channel, at the brand's scale. The first step was a credential in a repository. The last was a board-level brand-integrity event. Nothing changed except that the context was connected to the same credential.